WordPress 2.1.3 has been released and I have updated this site to WordPress 2.1.3.
These releases include fixes for several publicly known minor XSS issues, one major XML-RPC issue, and a proactive full sweep of the WordPress codebase to protect against future problems.
WordPress 2.1.2 has been released and I have updated this site to WordPress 2.1.2.
It is an emergency release, so I urged all of you to upgrade it.
Here is what happen, copied + pasted:
This morning we received a note to our security mailing address about unusual and highly exploitable code in WordPress. The issue was investigated, and it appeared that the 2.1.1 download had been modified from its original code. We took the website down immediately to investigate what happened.
It was determined that a cracker had gained user-level access to one of the servers that powers wordpress.org, and had used that access to modify the download file. We have locked down that server for further forensics, but at this time it appears that the 2.1.1 download was the only thing touched by the attack. They modified two files in WP to include code that would allow for remote PHP execution.
Remember to overwrite EVERY files/folders except those in the ‘wp-content’ folder.
WordPress 2.1.1 has been released and I have updated this site to WordPress 2.1.1.
I have updated this site to WordPress 2.1 RC1. The good news is I updated some of my plugins to make use of the “technology” of WordPress 2.1 but the bad news is that it is not backward compatible (I am too lazy/busy to make it backward compatible). I will release them when WordPress 2.1 goes gold.
Updated Plugins For WP 2.1:
» WP-Ban 1.10
» WP-DBManager 2.10
» WP-PageNavi 2.10
» WP-Polls 2.14
» WP-PostRatings 1.10
» WP-PostViews 1.10
» WP-RelativeDate 1.10
» WP-Stats 2.10
» WP-UserOnline 2.10
» WP-ServerInfo 1.00 (New Plugin – Display Your Host’s Server PHP and MYSQL Information On Your Dashboard)
Current Plugins That Will Work With WP 2.1:
» WP-EMail 2.07
» WP-Print 2.06
Plugins Not Tested With WP 2.1:
» WP-WAP 2.00
WP-DBManager and WP-ServerInfo cannot work side by side due function name conflicts, I will update WP-DBManager ASAP and also to make it work with WP 2.1 if it doesn’t
EDIT: WP-DBManager will be updated to 2.10
Thanks to a fellow member (Turk) in GaMerZ.Forums, I came to know that WordPress 2.1 is in the beta stages, beta 1 to be exact. Some of my plugins maybe broken with WordPress 2.1 like WP-PageNavi and WP-Stats, but I had already fixed them. If you need it to test it out, feel free to drop me an email.
If you find any of my plugins that are not compatible with WordPress 2.1, please let me know so that I do not need to test all my plugins against WordPress 2.1
Now I need some ideas, I have been thinking the name of my new downloads plugin, but just could not come out with any name nice. WP-Downloads and WP-Download-Manager is taken.
I have the following in mind:
WP-Download (without the s)
Any suggestions are welcomed =)