Wordpress 2.0.6 Released to Fix Wordpress Template.php Exploit?

Upgrade of Wordpress 2.0.6 is released it includes an important security fix and they recommended everyone upgrades their Wordpress installations.

Some of the important features in the release are:

  • Several security fixes.
  • HTML quicktags now work in Safari browsers.
  • Comments are filtered to prevent them from messing blog layouts.
  • Compatibility with PHP/FastCGI setups.
  • For developers, a new anti-XSS function called attribute_escape(), and a new filter called “query” which allows you filter any SQL at runtime.

Maybe this release fixes the recently reported Wordpress template.php Exploit, which had WordPress users confused about applying patches. Download Wordpress 2.0.6 from http://wordpress.org/download/.

Leave a Reply