If you’re using WordPress, make sure and update to the latest version (3.0.2) as soon as possible. Especially if you have multiple authors with access to your blog/site.
Details about the security issue fixed:
This maintenance release fixes a moderate security issue that could allow a malicious Author-level user to gain further access to the site, addresses a handful of bugs, and provides some additional security enhancements. Big thanks to Vladimir Kolesnikov for detailed and responsible disclosure of the security issue!
The changes between 3.0.1 and 3.0.2 are pretty small and only these files were modified:
wp-admin/includes/file.php
wp-admin/includes/plugin.php
wp-admin/includes/update-core.php
wp-admin/plugins.phpwp-includes/canonical.php
wp-includes/capabilities.php
wp-includes/comment.php
wp-includes/functions.php
wp-includes/load.php
wp-includes/ms-files.php
wp-includes/version.php



Comments