Results 1 to 9 of 9

Thread: WordPress Critical Update - 3.0.4

  1. #1
    Thread Starter
    Veteran eyecool's Avatar
    Join Date
    Jul 2009
    Location
    United States
    Posts
    454
    Thanks
    6
    Thanked 83 Times in 66 Posts

    WordPress Critical Update - 3.0.4

    ***Hot off the Press***

    Update WordPress immediately! Critical! Mandatory! Call it what you want - bottom line, UPDATE!

    Although this update has nothing to do with your AppThemes, we don't want to see anyone's hard work with CP or JR compromised because of it. Please take a few minutes to upgrade your WordPress to the latest version, right now!

    If you're already running 3.0.3, only a few files are updated, here's the list from one of my installs:
    • wp-includes/version.php
    • wp-includes/formatting.php
    • wp-includes/kses.php
    • readme.html
    • wp-admin/includes/update-core.php


    The update will not affect your theme. Disable all plugins, update WordPress, enable all plugins.


    Note: If you're on DreamHost read this: http://www.dreamhoststatus.com/2010/...ustomer-sites/ (12/29/10)
    Note: If you're running WordPress 3.1-RC1, update to the current nightly release to receive the fix that was included in 3.0.4. (12/29/10)

    References:
    WordPress.org News Release
    WordPress.org Codex (now updated)
    Last edited by eyecool2; December 30th, 2010 at 12:29 AM. Reason: continued updates

    Make everything as simple as possible, but not simpler. - Albert Einstein

  2. The Following User Says Thank You to eyecool For This Useful Post:

    pepsi (December 29th, 2010)

  3. #2
    pepsi's Avatar
    Join Date
    Mar 2009
    Location
    New Zealand
    Posts
    14,883
    Thanks
    91
    Thanked 804 Times in 718 Posts
    Thanks for the heads up on this

  4. #3
    Founder dcowgill's Avatar
    Join Date
    Mar 2009
    Location
    San Francisco, CA
    Posts
    1,939
    Thanks
    66
    Thanked 135 Times in 99 Posts
    Yeah thanks for the quick post.

    Also, if you host your WordPress instance in the cloud (W3 Total Cache plugin), make sure to update it there too.

  5. #4
    Marketplace Seller ahikmahin's Avatar
    Join Date
    Aug 2010
    Location
    Australia
    Posts
    504
    Thanks
    32
    Thanked 52 Times in 42 Posts
    Thanks.. already updated

  6. #5
    horizen's Avatar
    Join Date
    Dec 2010
    Posts
    70
    Thanks
    7
    Thanked 1 Time in 1 Post
    Sorry dont want to sound like a twit - just curious - why dont we just not update to WP3.0.4 and wait until there is a major release like 3.1.0 and then update WP+JR or CP?

  7. #6
    Founder dcowgill's Avatar
    Join Date
    Mar 2009
    Location
    San Francisco, CA
    Posts
    1,939
    Thanks
    66
    Thanked 135 Times in 99 Posts
    Normally it's ok to wait for the next major release but this one patches a critical WordPress security issue.

    Once hackers figure this out, they'll launch their automated scripts to scour the web looking for older WP instances. You don't want to be on their list.

    It's better to be safe than sorry and update now.

  8. The Following User Says Thank You to dcowgill For This Useful Post:

    horizen (December 30th, 2010)

  9. #7
    Thread Starter
    Veteran eyecool's Avatar
    Join Date
    Jul 2009
    Location
    United States
    Posts
    454
    Thanks
    6
    Thanked 83 Times in 66 Posts
    Quote Originally Posted by horizen View Post
    Sorry dont want to sound like a twit - just curious - why dont we just not update to WP3.0.4 and wait until there is a major release like 3.1.0 and then update WP+JR or CP?
    It patches an XSS security bug in kses.php, which sanitizes posts. Left open (unpatched) it leaves an open door to monsters, like base64. Yes, eval(base64) is still going around. It lives because users don't patch their installations!

    Look at the top post in this thread.. only a few files are actually modified and those are critical!

    Make everything as simple as possible, but not simpler. - Albert Einstein

  10. The Following User Says Thank You to eyecool For This Useful Post:

    horizen (December 30th, 2010)

  11. #8
    Junior Member cslcpunk's Avatar
    Join Date
    Oct 2010
    Location
    Alaska
    Posts
    25
    Thanks
    4
    Thanked 0 Times in 0 Posts
    If we have already updated to Wordpress 3.0.4 does that correct the issue? or is it to correct a problem in that release? I am on board with fixing whatever needs fixing, just a little confused.

  12. #9
    Founder dcowgill's Avatar
    Join Date
    Mar 2009
    Location
    San Francisco, CA
    Posts
    1,939
    Thanks
    66
    Thanked 135 Times in 99 Posts
    Quote Originally Posted by cslcpunk View Post
    If we have already updated to Wordpress 3.0.4 does that correct the issue? or is it to correct a problem in that release? I am on board with fixing whatever needs fixing, just a little confused.
    Yep. You're fine then.

  13. The Following User Says Thank You to dcowgill For This Useful Post:

    cslcpunk (February 2nd, 2011)

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. update wordpress 3.02
    By kyostrife in forum Report ClassiPress Bugs
    Replies: 1
    Last Post: December 1st, 2010, 11:35 AM
  2. [SOLVED] Wordpress Version 3.02 update?
    By job888 in forum Report JobRoller Bugs
    Replies: 3
    Last Post: December 1st, 2010, 08:31 AM
  3. Replies: 1
    Last Post: November 14th, 2010, 04:37 PM
  4. Classipress update comin for Wordpress 3.0?
    By bellboy in forum ClassiPress General Discussion
    Replies: 2
    Last Post: June 2nd, 2010, 12:03 AM
  5. Critical Problem admin login server error 500
    By durhamcentral in forum Help Using ClassiPress
    Replies: 1
    Last Post: May 22nd, 2010, 02:31 PM