The WordPress team has released a security update for the world’s best bloggng software (John Chow dot Com is a featured WordPress Showcase blog). Anyone running WordPress 2.8 or 2.8.1 should upgrade to this latest version right away.
WordPress 2.8.2 fixes an XSS vulnerability. Comment author URLs were not fully sanitized when displayed in the admin. This could be exploited to redirect you away from the admin to another site. Download 2.8.2 or automatically upgrade from the Tools->Upgrade page of your blog’s admin.
The upgrade changes only 10 files and doesn’t touch the database. A simple upload and replace is all that’s required. Or you can use the auto upgrade feature built into the WordPress software.
Did you enjoy this post? Get John Chow Dot Com updates via email...
Stay up to date with all of John Chow’s tips for making money online and blog posts by subscribing via email. Your email will be kept private and never shared with anyone.














One of the most common complaint (or excuse) I hear from potential new bloggers is they don’t know how to install WordPress. Terms like FTP and CPanel are like a foreign language and setting up a database might as well be setting up the space shuttle for a launch. Because of the technology barrier, many would-be bloggers never start their blogs...