WordPress 3.6.1

WordPress 3.6.1 has been release. This is a maintenance and security release, so please upgrade as soon as you get the chance.

This .1 release fixes 13 bugs and the below security issues:

  • Block unsafe PHP unserialization that could occur in limited situations and setups, which can lead to remote code execution. Reported by Tom Van Goethem.
  • Prevent a user with an Author role, using a specially crafted request, from being able to create a post “written by” another user. Reported by Anakorn Kyavatanakij.
  • Fix insufficient input validation that could result in redirecting or leading a user to another website. Reported by Dave Cummo, a Northrup Grumman subcontractor for the U.S. Centers for Disease Control and Prevention.
  • Additionally, we’ve adjusted security restrictions around file uploads to mitigate the potential for cross-site scripting.

Download: WordPress 3.6.1

1 Star2 Stars3 Stars4 Stars5 Stars (44 votes, average: 3.98 out of 5)

WP-Polls, WP-PostRatings, WP-PostViews, WP-Email Updated

I have updated the following plugins:

Now all AJAX requests are handled by /wp-admin/admin-ajax.php. Previously it is handled via the plugin PHP file itself by assuming that wp-load.php is always 2 levels down from the plugin file. But since you can have your WordPress in any folders, custom loading of wp-load.php is not possible as the path to wp-load.php varies from server to server.

While I am at it, I added nonce check for AJAX calls to WP-Polls, WP-PostRatings and WP-Email. Let me know if you run into problems via WordPress Support Forums, My Forums (if you are already registered) or via email (lesterchan AT gmail).

PS: Kindly refer to https://lesterchan.net/wordpress/2012/06/05/ajax-not-working-for-wp-email-wp-polls-wp-postratings-or-wp-postviews/ if you ran into problems.

1 Star2 Stars3 Stars4 Stars5 Stars (136 votes, average: 3.97 out of 5)

My Plugins Update June 2006

WP-DBManager 2.05
» FIXED: Database Table Names Not Appearing Correctly
» NEW: DBManager Administration Panel Is XHTML 1.0 Transitional
» Download WP-DBManager 2.05

WP-PageNavi 2.02
» NEW: Added Drop Down Menu Style Of Page Navigation
» Download WP-PageNavi 2.02

WP-Polls 2.1
» NEW: Poll Is Now Using AJAX
» NEW: Ability To Close/Open Poll
» NEW: Added Poll Option For Logging Method
» NEW: Added Poll Option For Who Can Vote
» NEW: Added Poll Results Footer Template Variable (Used When User Click “View Results”)
» NEW: Added The Ability To Delete All Poll Logs Or Logs From A Specific Poll
» NEW: Poll Administration Panel And The Code That WP-Polls Generated Is XHTML 1.0 Transitional
» Download WP-Polls 2.1

WP-PostRatings 1.02
» NEW: Fading In/Put Effect After You Rate A Post
» NEW: Rating Voting And Rating Results Are On The Same Image
» NEW: Added Rating Option For Logging Method
» NEW: Added Rating Option For Who Can Rate
» NEW: Added Rating Results Image To Get Highest Rated Stats
» NEW: Rating Administration Panel And The Code That WP-PostRatings Generated Is XHTML 1.0 Transitional
» Download WP-PostRatings 1.02

WP-Print 2.05
» NEW: Added Print Options In WP Administration Panel Under ‘Options -> Print’
» NEW: Print Administration Panel And The Code That WP-Print Generated Is XHTML 1.0 Transitional
» FIXED: Comment’s Content Formatting
» Download WP-Print 2.05

My WordPress Plugins Page

1 Star2 Stars3 Stars4 Stars5 Stars (91 votes, average: 3.97 out of 5)