Today I received a prompt to upgrade my wordpress installation to WordPress 2.3.3, It is an urgent security release that caters to flaw wrt XML-RPC implementation, here are the details.
If you have registration enabled a flaw was found in the XML-RPC implementation such that a specially crafted request would allow a user to edit posts of other users on that blog. In addition to fixing this security flaw, 2.3.3 fixes a few minor bugs. If you are interested only in the security fix, download the fixed version of xmlrpc.php and copy it over your existing xmlrpc.php. Otherwise, you can get the entire release here.

Also, there is a vulnerability in the WP-Forum plugin that is being actively exploited right now. If you are using this plugin, please remove it until an update is available from its author.

The upgrade only took 3 minutes, so if you are using version 2.3.2 I’ll advice you to upgrade ASAP.

~Himanshu~

Advertisements