A new release of WordPress has just been released.
The highlights of this release:
- A fix for the Trackback Denial-of-Service attack that is currently being seen.
- Removal of areas within the code where PHP code in variables was evaluated.
- Switched the file upload functionality to be whitelisted for all users including Admins.
- Retiring of the two importers of Tag data from old plugins.
They call it a “Hardening Release”, and it is – as always – recommended to upgrade as soon as possible. I have already upgraded CleverWP.com .. Just in case ![]()
Read more about the release here: http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/
Go here to download it: http://wordpress.org/download/


{ 2 comments… read them below or add one }
I don’t understand why they released the new version so quickly after the last update 2 months ago.
I don’t see any changing in this new version. It’s not really necessary to upgrade.
Hi VC
Maybe not, but whenever there are security releases, I update. Trackback DOS attacks? Haven’t heard about those, but now I do not have to, I hope.