Skip to main content

Posts

Showing posts from April 15, 2012

WordPress 3.3.2 (and WordPress 3.4 Beta 3)

WordPress 3.3.2 (and WordPress 3.4 Beta 3)    阅读原文» WordPress 3.3.2 is available now and is a security update for all previous versions. Three external libraries included in WordPress received security updates: Plupload (version 1.5.4), which WordPress uses for uploading media. SWFUpload, which WordPress previously used for uploading media, and may still be in use by plugins. SWFObject, which WordPress previously used to embed Flash content, and may still be in use by plugins and themes. Thanks to Neal Poole and Nathan Partlan for responsibly disclosing the bugs in Plupload and SWFUpload, and Szymon Gruszecki for a separate bug in SWFUpload. WordPress 3.3.2 also addresses: Limited privilege escalation where a site administrator could deactivate network-wide plugins when running a WordPress network under particular circumstances, disclosed by Jon Cave of our WordPress core security team, and Adam Backstrom . Cross-site scripting vulnerability when making URLs clickable,