John Chow dot Com Free WordPress Installation - Start Your Blog Today!
 

WordPress 2.6.5 Available for Download

written by John Chow on November 25, 2008

How to make $593 in less than one hour

WordPress has released version 2.6.5 of their blogging software. This is a security release so everyone must upgrade.

The security issue is an XSS exploit discovered by Jeremias Reith that fortunately only affects IP-based virtual servers running on Apache 2.x. If you are interested only in the security fix, copy wp-includes/feed.php and wp-includes/version.php from the 2.6.5 release package.

2.6.5 contains three other small fixes in addition to the XSS fix. The first prevents accidentally saving post meta information to a revision. The second prevents XML-RPC from fetching incorrect post types. The third adds some user ID sanitization during bulk delete requests. For a list of changed files, consult the full changeset between 2.6.3 and 2.6.5.

WordPress is skipping version 2.6.4 and jumping from 2.6.3 to 2.6.5 to avoid confusion with a fake 2.6.4 release that made the rounds. There is not and never will be a version 2.6.4.

Download WordPress 2.6.5

Did you enjoy this post? Get John Chow Dot Com updates via email...

Stay up to date with all of John Chow’s tips for making money online and blog posts by subscribing via email. Your email will be kept private and never shared with anyone.

{ 31 comments }

Affiliate Confession November 25, 2008 at 7:19 pm

Cool, I’ll have to run over and get it.

Chris Jacobson November 25, 2008 at 10:07 pm

Already updated and ready to go! :)

Trevor November 25, 2008 at 10:32 pm

I’ve just used the security fix only.

No point in upgrading the whole thing when security is the only thing to worry about.

The big thing is Wordpress 2.7. It looks so slick.

Abdul November 27, 2008 at 2:59 am

Yeah, there is no way anyone can miss that!

Taris J November 26, 2008 at 6:55 am

Thanks for the heads up as to how to simply upgrade the two files for the security fix – very useful for those that don’t want to go through a huge pain in the butt!!

E-Business Blog November 25, 2008 at 7:47 pm

unfortunately, I have upload an older version of WP

WinCashPlayGames November 25, 2008 at 8:22 pm

http://playcow.com I just upload the older version of wordpress, and now it release a new one again, update too often. i don’t even have time to update. LOL

Study Babes November 26, 2008 at 12:07 am

your site is wordpress??

SodLogan November 26, 2008 at 5:58 am

I don’t think so. In fact, it uses ASP instead of PHP.

Study Babes November 26, 2008 at 9:35 am

:D

Abdul November 27, 2008 at 4:00 am

I wonder which blogging platform uses ASP, I’d love to know because I know ASP 3.0 and would love my blog to work on it!

Abdul November 27, 2008 at 4:01 am

Darn it, it’s not a blog just some other Games website!

Ari Lestariono November 25, 2008 at 9:11 pm

Can anyone tell me, the benefit and importnce of these new release wordpress and what will be the impact?thx in advance

John Chow November 25, 2008 at 9:28 pm

Sure! If you don’t want to get hacked, upgrade!

Seo Creations November 26, 2008 at 5:16 am

Yup, I got 20 blogs hacked out of 100s

Abdul November 27, 2008 at 3:22 am

You’re kidding me!! In this case, the hacker would have hacked every blog before the update came out, I mean it takes a little time!

Alex at Net-Entrepreneur.com November 26, 2008 at 7:22 am

What exactly happens when someone hacks your blog? (no need to demonstrate on mine :) I’m running the latest wp)

But seriously, I keep hearing about blogs being hacked here and there because they ran an older version with security holes. But what does it mean?

Cheers,
Alex

PlayGameMakeMoney November 25, 2008 at 9:36 pm

As John said, “If you dont’ wanna get hacked, Upgrade dew.

TYCP Entertainment Magazine November 27, 2008 at 4:11 pm

If you want your blog to be secured, then you need to upgrade right away.

uwak November 25, 2008 at 10:44 pm

thanks for information…the same topic in shoe blog…

Brady Ware November 25, 2008 at 11:18 pm

Wow figures. I just bought a domain figured out how to get wordpress installed and now I need to update it. Well I guess no time like the present to learn, I’ve got another few hours to burn on frustration.

Deborah November 26, 2008 at 5:27 am

Search for plug-ins. There is an upgrade plug-in you can install and upgrading will only involve a few clicks from your WP admin pages…

BusinessX November 25, 2008 at 11:42 pm

Great heads up about the 2.6.4, I did not know about that! Hope measures are being taken to prevent that from happening again.

Google SEO Tools November 26, 2008 at 6:56 am

Be carefull about that 2.6.4…..

Alex Fraiser November 26, 2008 at 11:01 am

I don’t understand why so many people complain about getting WordPress upgraded. A big time saver is the WordPress Automatic Upgrade: http://wordpress.org/extend/plugins/wordpress-automatic-upgrade/

Debo Hobo November 26, 2008 at 11:44 am

All done…upgraded and ready to go…:)

Forex Directory November 26, 2008 at 2:29 pm

Just finished the upgrade, harmless like usually ;-)

Ryan McLean November 26, 2008 at 2:31 pm

When is wordpress 2.7 being released?
That one I am looking forward to.

Make money online November 26, 2008 at 4:54 pm

nope, i will wait for v 2.7
its heck to upgrade stuffs..

titan November 27, 2008 at 6:28 am

i guess, i will upgrade my wordpress soon. :)

TYCP Entertainment Magazine November 27, 2008 at 4:13 pm

I’ve always loved the Automatic Upgrade plugin. Makes thing smooth & easy.