WordPress升级至2.8.4
又又又又……升了!还是安全方面的漏洞吧..官方还是用的“强烈建议”这个词,So,更新吧~
Yesterday a vulnerability was discovered: a specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password would be emailed to the account owner. This doesn’t allow remote access, but it is very annoying.
We fixed this problem last night and have been testing the fixes and looking for other problems since then. Version 2.8.4 which fixes all known problems is now available for download and is highly recommended for all users of WordPress.
大概意思是,昨天检查出一个漏洞,攻击者可以通过一个特定的网址绕过安全检查,验证用户并且重设密码。结果会导致数据库中第一个账户(通常是管理员帐户)的密码被重置,并且一个新的密码会被电邮至帐户所有者。这并不允许远程访问,不过也是很讨厌的。昨晚我们已经修复了这个问题,并且不断测试其他可能会出现的情况。现在提供的WordPress2.8.4已经修复了所有已知的问题,强烈建议所有WordPress用户更新。