WordPress 2.8.4 was released on August 12th, 2009 as is a security release.
Yesterday a vulnerability was discovered: a specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password would be emailed to the account owner. This doesn’t allow remote access, but it is very annoying.
We fixed this problem last night and have been testing the fixes and looking for other problems since then. Version 2.8.4 which fixes all known problems is now available for download and is highly recommended for all users of WordPress.
Order your WordPress upgrade today and keep up to date.
WordPress 2.8.3 was released on August 3rd, 2009 as is a security release.
Several folks in the community dug deeper and discovered areas that were overlooked. With their help, the remaining issues are fixed in 2.8.3. Since this is a security release, upgrading is highly recommended.
Order your WordPress upgrade today and keep up to date.
Via Watershed Studio:
Now through August 31st, 2009 you can purchase OIOpublisher for just $39 (normally $47) by using coupon code “BLUE-WSHED” (no quotes). If you’re unfamiliar with OIOpublisher, it is a PHP based ad platform with a focus on performance, control and ease of use. It allows you to easily serve advertising on your blog or website and keep 100% of the revenue you bring in.
[Update: August 2010 OIOpublisher Coupon Code - Now through August 31st, 2010 you can purchase OIOpublisher* for just $37 (normally $47) by using coupon code "SOLAR-WSHED" (no quotes).]