Another upgrade of WordPress has released today and this time it’s about a security hole. This upgrade is specially for the persons who allow open registrations on their blogs. If it’s your case, you should update your WordPress to the latest version as soon as possible. Here is the note:
If you allow open registration on your blog, you should definitely upgrade. With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password. The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit. However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password. Stefan Esser will release details of the complete attack shortly. The attack is difficult to accomplish, but its mere possibility means we recommend upgrading to 2.6.2.
Anyways, I recommend you to upgrade to the latest version, and I would like to take advantage of this post to recommend you the WordPress Automatic Upgrade Plugin, which you can upgrade your wordpress with simple clicks.
So once upgraded, feel safe to register on this blog, remember that good features are coming!




Hey! my name is Javier but you can call me Javo, everybody does.
Everyone that uses WordPress should download that plugin. Makes things so much easier.
Thanks for the plugin buddy, should help when I actually upgrade sometime
Dennis Edells last blog post..Merging Blogs: Internet and Offline Markeing Together. I’d Like Your Thoughts.
Weird commentluv issue…Merging Blogs is not my latest post
Dennis Edells last blog post..Merging Blogs: Internet and Offline Markeing Together. I’d Like Your Thoughts.
Thanks for the plugin Javo,
Mike
wordpress is upgrading fast, I’m tired of upgrading them already, grateful you give the link for the plugin, will try it soon
Hey, I was also thinking of getting that plugin, it is pretty slick!
Abduls last blog post..Follow or NoFollow? – Where the Difference Lies