WordPress 2.8.4 Released

As predicted, WordPress 2.8.4 has been released. No surprise here, after news about the admin password reset “exploit” issue surfaced yesterday. Yeah, there’s some arguments over whether it’s a security issue or not, but it can be pretty annoying if you get hit by it.

It’s highly recommended you upgrade immediately. This is a pretty minor upgrade as it’s supposed to only fix the one bug. Anyone know the record of most point releases on a single branch?

By the way, if you ever come across an undiscovered WordPress security issue, make sure you know the correct way to report it. Blabbing about how you used it on sites you don’t own/administer under the guise of “proof-of-concept” is not the correct way,.

15

Jun

2011

WordPress 2.8.3 Security Fix: Admin Password Reset

Just found out about a potentially annoying WordPress 2.8.3 security issue. Basically, anyone can reset your admin password without any confirmation. This could be a major annoyance if someone decides to reset your admin password constantly.

I just tested this (on one of my own test blogs, of course) and it actually works. After anyone visits the URL, it sends the new password to your e-mail address. If you’re in the middle of doing something in your admin panel, you may have to login again.

Luckily it’s just a one line fix, which you might want to implement if some annoying person thinks it’s funny to reset your password. WordPress 2.8.3 was just released a little more than a week ago. Do I hear a WordPress 2.8.4 coming soon?

If this happens to you, and for some reason you don’t receive an e-mail with the new password and find you can’t login to your blog, you might want to look into resetting your WordPress password through phpMyAdmin.

15

Jun

2011

Theme Battle #2 – Bravissimo vs. Photabulous

After the success of our first theme battle, regular Theme Lab commentator and designer Keith decided to volunteer a couple great PSD designs to our next one. The two screenshots are below. Simply vote for the one you’d rather see coded into a fully functional WordPress theme.

Bravissimo

Bravissimo

Photabulous

Photabulous

Read on to vote. You’ll need to vote on the actual site, so leave your RSS readers for a second.

Read More

15

Jun

2011