WordPress 3.1.1 has been released. This maintenance and security release fixes 26 issues with the following highlights: Performance improvements Fixes for IIS6 support Fixes for taxonomy and PATHINFO (/index.php/) permalinks Fixes for various query and taxonomy edge cases that caused some plugin compatibility issues Regarding this release’s security fixes, “the first hardens CSRF prevention in the media uploader, the second avoids a PHP crash in certain environments when handling devilishly devised links in comments, and the third addresses an XSS flaw.” For most of you, 3.1.1 should be available as an automatic update via your Dashboard. If that isn’t working for you, you can download WordPress and perform a manual update.
[Continue Reading...]
Comment Rating Plugin Fixes Security Vulnerability
If you use the Comment Rating plugin for your WordPress powered site, you are highly encouraged to upgrade to the latest version as it fixes a security vulnerability. More specifically, a Cross-site Request Forgery attack. According to the report at OSVDB.org which is an Open Source Vulnerability Database: The flaw exists because the application does not require multiple steps or explicit confirmation for unspecified sensitive transactions for the admin function. By using a crafted URL (e.g., a crafted GET request inside an “img” tag), an attacker may trick the victim into clicking on the image to take advantage of the trust relationship between the authenticated victim and the application. Such an attack could trick the victim into executing arbitrary commands in the context of their session with the application, without further prompting or verification. There is no known workaround for versions lower than 2.9.21. Kudos goes to KrebsOnSecurity for reporting […]
[Continue Reading...]