WordPress 2.8.4 Fixes a Security Vulnerability

August 12, 2009 at 9:00 AM · 2 comments

in Operations,PHP,Social Software

Less than two weeks ago, WordPress 2.8.3 was released in order to address a security vulnerability; before that, less than a month ago, WordPress 2.8.2 was released to address some other security issues…

Now we have WordPress 2.8.4, which according to Matt is a security release intended primarily to address a password reset vulnerability that allows baddies to sleaze past a password reset check.

If you operate WordPress blogs and did not yet upgrade from an earlier version of WordPress 2.8.x, you should strongly consider upgrading to this version. The customary testing procedure is recommended: download it, set it up in your testing environment and vet it through your test suite(s), prepare your CM machinery to handle the new version if it passes your tests, and deploy it to your production environment.

Previous post:

Next post: