Although it isn’t very long after WordPress 2.8.1 was released, WordPress 2.8.2 was just released today and is a security update which corrects a XSS vulnerability which was discovered.   Comment author URLs were not fully sanitized when displayed in the admin. This could be exploited to redirect you away from the admin to another site.

Due to this being a security update, it is strongly recommended that you upgrade your WordPress 2.8 installations as soon as possible.  This can quickly and easily be done via your WordPress administrator panel (for WordPress 2.7 and newer installations) via Tools –> Upgrade, or you can manually download it here

If you’d like to read the official announcement, you can see it here.

Want automatic updates? Subscribe to our RSS feed or
Get Email Updates sent directly to your inbox!
Tweet This | Digg This | Stumble it | Add to Del.icio.us | | Print This

Kyle Eslick

Kyle Eslick is WordPress enthusiast who took his passion for WordPress to the next level back in 2007 by launching WPHacks.com as a place to share hacks and review WordPress-related products. You can learn more about him by following his personal tweets here.

There Are 3 Responses So Far »

  1. I have updated already with no problems. I only saw it yesterday in my dashboard. Good to know that the security problem has been fixed.

  2. Dean Saliba says:

    Good to see WordPress are on top of this and released a patch so quickly. I know al ot of people moan about the amount of times they have to update but at least it makes your blog more secure.

  3. Dzinepress says:

    can use this with my existing WP theme, because i heard may be some themes are still not supporting this version, very much reserve about that issue, have any solution, other the backup.

Trackbacks/Pingbacks »

Leave a Reply