Outsource all your SEO work
 

Wordpress 2.6.2 Available for Download

written by John Chow on September 9th, 2008

I’ve just got the noticed on my Wordpress control panel that version 2.6.2 is now available for download. This is a security update so everyone who is running Wordpress should update to this latest version ASAP. This is especially true is you allow open registration on your blog.

If you allow open registration on your blog, you should definitely upgrade. With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password. The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit. However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password. Stefan Esser will release details of the complete attack shortly. The attack is difficult to accomplish, but its mere possibility means we recommend upgrading to 2.6.2.

Download Wordpress 2.6.2

Quit Your Day Job said on September 9th, 2008 at 4:05 am

Wow, interesting bug. Time to upgrade for sure.

Reply to this comment
Milo said on September 9th, 2008 at 4:37 am

Another update? It’s sick. So much time wasted in these incremental upgrades especially when you have a number of blogs. The automatic update plugin doesn’t work consistently.

I think this is the main reason why more heavyweight blogs are using products from sixapart.

I am seriously thinking of migrating…

Reply to this comment
Glen Allsopp said on September 9th, 2008 at 5:13 am

I wish we didn’t have to update so often, it is a whole ‘nother chore in itself

Reply to this comment
atlanta wedding photographer said on September 9th, 2008 at 6:20 am

I think that my webhost (hostmonster) is a little behind on the upgrade…i have to go into simplescripts to upgrade. It there another possible way to upgrade?

Reply to this comment
Ryan McLean said on September 9th, 2008 at 7:36 am

GRRRRRR!!!
I hate how wordpress keeps telling us to upgrade again and again and again and again….I am so frustrated.
I wish there was an easy way to upgrade atlanta but I don’t think there is an easy way…is there?

Reply to this comment
Abdul said on September 9th, 2008 at 7:58 am

Yea me too, I haven’t even upgraded to the last upgrade that came up!

Reply to this comment
Chris Jacobson said on September 9th, 2008 at 8:49 am

You guys should get the instant upgrade plugin.

Click once, click twice — done the upgrade!

Takes about 15 seconds.

Reply to this comment
Jake said on September 9th, 2008 at 11:57 am

This automatic upgrade plugin didn’t work too well on two of my blogs on which I tried it. Can’t be too bothered about these updates, my log homes site still runs on version 1.5.x. and it is readable.

I suppose I’ll do my next upgrades when Wordpress reaches 3.something and I’m sure even then I won’t be using any cool new features that come with it. I’ll just keep pushing that publish button every now and then. I can see the benefits for active plugin and widget users though.

Reply to this comment
TYCP Entertainment Magazine said on September 9th, 2008 at 1:16 pm

Jake, that’s crazy. You should at least upgrade to 2.5

Reply to this comment
How I Got A Job In The OC said on September 9th, 2008 at 8:27 am

Yea I remember that was a frustration for me at starting my last blog. Too many frequent updates.

Reply to this comment
atlanta wedding photographer said on September 10th, 2008 at 9:18 am

how is it that I now have a link on the word “webhost”? Strange and wonderful things I see…. . . . :mrgreen:

Reply to this comment
Fail Funnies said on September 9th, 2008 at 6:37 am

I have found that the auto-update plugin works great for this. I tried to upgrade manually and had a complete disaster with one of my sites. So much so that I had to rebuild the entire database and reconstruct. I heard about the exploit yesterday and yes, it is time to get up to date.

Reply to this comment
Abdul said on September 9th, 2008 at 8:00 am

Hey I heard there was an automatic upgrading plug-in, you can get that to upgrade automatically, although I am not too sure about it because you still have to upload that plug-in maually through an FTP client and I’m too lazy to do that!!

Reply to this comment
Stephie3679 said on September 9th, 2008 at 8:09 am

That plugin is great. Wordpress always has upgrades and I found with the automatic update plugin works best. Thanks for letting me know about the security update.

Reply to this comment
m4stono said on September 9th, 2008 at 6:45 am

maybe sometime I will create my first wordpress blog

Reply to this comment
Freeman said on September 9th, 2008 at 7:30 am

You should! I love the Wordpress format! It makes blogging really enjoyable! :smile:

Reply to this comment
Abdul said on September 9th, 2008 at 8:04 am

oh so you’re still running at blogger eh… Get on my blog or just click here to know why I switched to wordpress and what might ruin your blog’s presence on the Internet FOREVER!
Well not actually forever, but a long time!
Mark my words, this happens to almost every blog that gets famous on blogger and you don’t want that to heppen to you!

Reply to this comment
DoublePlus Ecommerce said on September 9th, 2008 at 6:49 am

Coolio. Thanks for the security tip. Guess I know what will take up a couple of hours of my time this afternoon :(

Reply to this comment
Brad said on September 9th, 2008 at 7:10 am

:/ I haven’t finished updating all my other blogs from the last update. They are updating the software a little too much.

Reply to this comment
Andy Crofford said on September 9th, 2008 at 8:04 am

That is what I used to think. I found a great plugin that helps me update my WordPress blogs very quickly and it works like a charm. It is called Instant Upgrade.

Reply to this comment
Freeman said on September 9th, 2008 at 7:28 am

Oh yikes! I’m glad they are atleast on top of things! Security risks scare me! I don’t know what I would do if someone screwed with my passwords…find them and…well you get the the point… :twisted:

Reply to this comment
Ryan McLean said on September 9th, 2008 at 7:37 am

So John is there an easier way to update (like an automatic way) so I don’t have to keep accessing my files. Because this is really annoying me

Reply to this comment
Freeman said on September 9th, 2008 at 7:48 am

Who is your host Ryan? Some hosts allow you to easily and automatically update. I have Dreamhost and I can do it through my hosting panel with the touch of a button!

Reply to this comment
Abdul said on September 9th, 2008 at 8:05 am

Well you can get it’s plug-in as well to make it more automated once and for all!

Reply to this comment
Ryan said on September 9th, 2008 at 7:47 am

Thanks for the heads up… I’ll definitely get on to that.

Reply to this comment
revenue said on September 9th, 2008 at 7:50 am

Yes that is true and i have already update it, well i use the wordpress auto upgrade and all happen perfectly , and my blogs automatically upgrade to the latest version, download it from the wordpress extend. Just activated it and press upgrade that’s all :)

Reply to this comment
Nebraska SEO said on September 9th, 2008 at 8:12 am

Pain in the butt!

But it’s incredibly important to do the security updates as quickly as possible. I know people that have had multiple sites pwned because of an unsecure script on just one of them.

Reply to this comment
ZK said on September 9th, 2008 at 8:38 am

Its painful to keep updating wordpress every 40 days

Reply to this comment
Chris Jacobson said on September 9th, 2008 at 9:17 am

Automatic plugin. ;)

Reply to this comment
Steven-Sanders said on September 9th, 2008 at 8:49 am

It seems like everytime I get the bug worked out between my theme and the newest version of wordpress, they come out with another.

It’s a never ending battle.

Reply to this comment
Jake said on September 9th, 2008 at 1:40 pm

Backdoor update maybe? Wordpress could first run the update via plugin and widget providers to give them time to iron out any problems. Would it help? I sure don’t know, but in this case automatic update services would have something to work with.

Reply to this comment
Johan Cyprich said on September 9th, 2008 at 11:05 am

Why can’t there be a version of WordPress that works properly? Why are there all of these security updates? PHP is not the best language for building secure and stable applications.

Reply to this comment
Amanda said on September 9th, 2008 at 11:17 am

Maybe they should start combining updates or something. I JUST upgraded.. It’s hard to keep up with them almost if you don’t pay attention.

Reply to this comment
Pheak T said on September 9th, 2008 at 12:48 pm

someone should do a final update for wordpress so it will automatically prompt you to download the updates when there is one..sort of like windows update. (i hope no one else mentioned this already, if so, good idea :razz: )

Reply to this comment
TYCP Entertainment Magazine said on September 9th, 2008 at 1:20 pm

The upgrades are crazy, but people should be glad that they don’t ignore bugs.

Reply to this comment
CoolProducts said on September 9th, 2008 at 2:38 pm

I will definitely be updating my personal blog tonight. Seems like it shouldn’t be too difficult. I agree with everyone else though; there seems to always be new updates waiting for me on my dashboard.

Reply to this comment
100kjob said on September 9th, 2008 at 4:59 pm

This may be off topic a bit, but you just gained 600+ readers for the last couple of days, amazing!

Reply to this comment
Thibaut said on September 10th, 2008 at 7:51 am

Hum, seem now I don’t have time to blog as I keep on upgrading the 10 Wordpress blogs I own. I hope we will have soon an automatic Wordpress update like Mozilla :smile:

Reply to this comment
Steven-Sanders said on September 10th, 2008 at 2:08 pm

I used the Wordpress Automatice Upgrade Plugin for the first time today. My heart was racing everytime I hit the “Next Step” button as I went through the upgrade process.

I fully expected it to crap out on me, and cause me to restore my backups and my themes folders.

Tick, Tick, Tick… I waited. As if a bomb would explode any minute. Then… It happened.

My version had successfully upgraded with no errors! This plugin is awesome!

You can get it here: http://techie-buzz.com/wordpress-plugins/wordpress-automatic-upgrade-12-release.html

Reply to this comment
Fat Tony69 said on September 10th, 2008 at 2:23 pm

I am not going to update. To be honest, I am fed up with wordpress. They don’t even protect their PHP. Sure this helps, but I have to recode all my files. Here is what I am talking about.

http://thebestforumever.com/coding-lair/3425-wordpress-flaws.html#post51802

Reply to this comment
John D said on September 11th, 2008 at 4:52 am

Thanks for the headsup about the update. Sure, it might take a little bit of your time to update WP, but in the end, security is No. 1# priority.

Reply to this comment
titan said on September 11th, 2008 at 5:58 am

hoho. i just update to 2.6.1. I will update the latest one soon. Looks good huh!

Reply to this comment
Alex Kim said on September 11th, 2008 at 8:38 am

Yay! I just upgraded mine last night.

Reply to this comment
Kiniku.net said on September 11th, 2008 at 11:56 am

Oh, i’ve got something else to say, i think you have to put back the category widgets on the sidebar… just to make it handy for us to switch category because we don’t need to wait another seconds to go back to frontpage…

Reply to this comment
atlanta wedding photographer said on September 11th, 2008 at 1:50 pm

Has anyone lost all their wordpress from the upgrade. Any suggests for the best way. Meaning does anyone put it on a separate or external HD?

Reply to this comment
ssroslan said on September 16th, 2008 at 7:18 pm

I got a problem after successfully upgrading to 2.6.2. My theme’s sidebar suddenly appear at the bottom of the page. and this is only happen on the homepage only. All blog post page act as normal. I’ve tried to change to other themes but it still the same. I’m thinking of re-installing my wordpress if i still cannot find a solution by end of the week. Anybody facing the same problem? Any help from you guys is very much appreciated.

Reply to this comment
Linn said on September 22nd, 2008 at 9:30 pm

I am starting to use wordpress too, still learning.

so, autoupgrades are fantastic or not? coz after reading all your comments, it got me thinking, maybe manual upgrades would be a bit better while deactivate the plug-ins, ftp newer files only mode and activate back the plug-ins, will it work?

cheers in advance for the answers.

Reply to this comment

Sorry, the comment form is closed at this time.