WordPress 3.5.2

WordPress 3.5.2 has been released and this is a security fix which fixes 12 bugs including the following security issues:

  • Blocking server-side request forgery attacks, which could potentially enable an attacker to gain access to a site.
  • Disallow contributors from improperly publishing posts, reported by Konstantin Kovshenin, or reassigning the post’s authorship, reported by Luke Bryan.
  • An update to the SWFUpload external library to fix cross-site scripting vulnerabilities. Reported by mala and Szymon Gruszecki.
  • Prevention of a denial of service attack, affecting sites using password-protected posts.
  • An update to an external TinyMCE library to fix a cross-site scripting vulnerability. Reported by Wan Ikram.
  • Multiple fixes for cross-site scripting. Reported by Andrea Santese and Rodrigo.
  • Avoid disclosing a full file path when a upload fails. Reported by Jakub Galczyk.

You ae advised to upgrade immediately.

Download: WordPress 3.5.2 or visit Dashboard -> Updates in your site admin to update now.

1 Star2 Stars3 Stars4 Stars5 Stars (57 votes, average: 3.95 out of 5)

WordPress 2.5 Release Date

Accordingly to Lorelle, WordPress 2.5 will be released before WordCamp Dallas.
As taken from WordCamp Dallas website:

The Dallas 2008 WordCamp spans two days, with the first day focusing primarily on general user topics and the second day primarily on developer topics, with some overlap.

In this case, WordPress 2.5 should be out on either 28th March 2008 or 29th March 2008.

1 Star2 Stars3 Stars4 Stars5 Stars (19 votes, average: 3.95 out of 5)

WordPress 3.5 RC3

WordPress 3.5 RC3 has been released, I am expecting it to be the last RC and we will see the final WordPress 3.5 sometime within this week. No idea whether they will meet the originally targeted date of 5th December 2012.

  • Final UI improvements for the new media manager, based on lots of great feedback.
  • Show more information about uploading errors when they occur.
  • When inserting an image into a post, don’t forget the alternative text.
  • Fixes for the new admin button styles.
  • Improvements for mobile devices, Internet Explorer, and right-to-left languages.
  • Fix cookies for subdomain installs when multisite is installed in a subdirectory.
  • Fix ms-files.php rewriting for very old multisite installs.

Here is a list of pending issues (6 left): http://core.trac.wordpress.org/report/5

Download: WordPress 3.5 RC3

1 Star2 Stars3 Stars4 Stars5 Stars (113 votes, average: 3.94 out of 5)