WordPress 2.9.2 Released – Security Fix

WordPress 2.9.2 was released just a few minutes ago to address a security problem dealing with the Trash feature.

When WordPress implemented the new feature they failed to change the permissions granted when the post is in the trash. This means that an unauthenticated user cannot see the post, however an authenticated user can no matter what privileges they have, even ’subscriber’.

There are probably a few other bug fixes in this version but they were not part of the release announcement. If your site only has one author and no registered users, this upgrade is not critical.

4

4 responses to “WordPress 2.9.2 Released – Security Fix”

  1. Thanks for your post. I have tested 2.9.2 with the automatic upgrade and a manual upgrade on a couple of websites and both seem to work okay, so far. Keeping my fingers crossed.

Newsletter

Subscribe Via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

%d bloggers like this: