SearchForecast Marketplace

Upgrading to WordPress 2.8.5

Posted by: dragonblogger  //  Category: blogging

wordpress

In an effort to keep your WordPress installations as secure as possible, WordPress 2.8.5 is released which closes up some security gaps and helps your installation become more secure.

The primary fixes for version 2.8.5 of WordPress include:

* A fix for the Trackback Denial-of-Service attack that is currently being seen.
* Removal of areas within the code where php code in variables was evaluated.
* Switched the file upload functionality to be whitelisted for all users including Admins.
* Retiring of the two importers of Tag data from old plugins.

The company recommends all WordPress users to upgrade to 2.8.5 as soon as possible to minimize your security risks, they also have listed a link to the WordPress Exploit Scanner to use and scan your website to see if your site may have been compromised and there are any possible “risky” files or intrusions.

One note the WP-Exploit Scanner tries to allocate 256MB by default and this can cause a crash on some web hosting providers where you are on a shared hosting plan with a Memory limit. You can edit the plug-in php and turn down or up the amount of memory you want the scanner to use by adjusting this line:
define( ‘WP_MEMORY_LIMIT’, ’256M’ );

I have upgraded all 7 of my managed blogs to WordPress 2.8.5 this morning and have not seen any issues, I didn’t do the automatic upgrade though and did the manual install (is faster when you run so many blogs).

-Dragon Blogger

Related posts:

  1. WordPress 2.8.6 Released: Upgrade Now The latest fix Wordpress 2.8.6 addresses vulnerabilities with sites who have multiple authors and uploads that can be exploited to...
  2. WordPress 2.8.4 Security Update Yesterday I updated all 7 of my blogs to WordPress 2.8.4 to address the security fix that was mentioned below...
  3. Dealing with a Hacked WordPress Blog Wordpress php files can become hacked and your blog can be compromised, look for aWYoZnVu string in your .php files...
  4. Upgrade to WordPress 2.9.2 Upgrading to Wordpress 2.9.2 will close the security hole where contributors can see posts in your trashcan even if they...
  5. Find System Statistics with WP Security Scan Wordpress plugin WP Security Scan can tell you some great information about your system settings for your blog, like memory...


If you enjoyed this post, subscribe to DragonBlogger.com
via FaceBook, Twitter, RSS or Email
or
Enter your email and subscribe now!
Email:

Written by dragonblogger (1110 Articles Published)

Working in the IT Industry for over 10 years and specializing in web based technologies. Dragon Blogger has unique insights and opinions to how the internet and web technology works. An Avid movie fan, video game fan and fan of trying anything and everything new.

Follow dragonblogger on Twitter @dragonblogger

Tags: , , , , , , , , , , ,

6 Responses to “Upgrading to WordPress 2.8.5”

  1. Heather Kephart (58 comments) Says:

    Oh Geez, not again! I’m always afraid I’m going to delete my blog when I upgrade.
    Oh well, I suppose I should quit bitching and be appreciative that WordPress stays on top of these things (and you too!). Off to upgrade…
    Heather Kephart´s last blog ..Fuzzmail sheds light on what is hidden My ComLuv Profile

    [Reply]

    dragonblogger (1957 comments) Reply:

    This upgrade was pretty painless, but always back up your wordpress first

    [Reply]

  2. matblogger (1 comments) Says:

    Coincidentally I just upgraded my blog to 2.8.5. Frankly I’m not sure if its a good idea for wordpress to be coming out with so many new updates frequently. But with the automatic upgrade its typically painless, so I cant complain much :)
    matblogger´s last blog ..So how do you get an iTunes account if you are in Malaysia? My ComLuv Profile

    [Reply]

    dragonblogger (1957 comments) Reply:

    They are security fixes and a necessity, these versions aren’t just for the same of adding features. Consider them like you would Windows OS patches, they are needed.

    [Reply]

  3. Harsh Agrawal (3 comments) Says:

    Saw this update Yesterday and the first thing which I did
    was Backup my Db and updated the wordpress. Though wordpress are releasing very quick update.. :|

    [Reply]

  4. festivalplanet (1 comments) Says:

    This fix is to plug a possible security issue and i dont care how often they release such updates. The patch is simple and quick to install and i cannot believe WordPress is still free. Its awesome.
    festivalplanet´s last blog ..Auckland gets new music festival My ComLuv Profile

    [Reply]

Leave a Reply

CommentLuv Enabled

This site uses KeywordLuv. Enter YourName@YourKeywords in the Name field to take advantage.

Comments links could be nofollow free.