The key password loophole and its repairing method in WordPress

Source: Internet
Author: User
Keywords WordPress Patches

Intermediary transaction http://www.aliyun.com/zixun/aggregation/6858.html ">seo diagnose Taobao guest cloud host technology Hall

WordPress is the most powerful and popular blogging program in the world. Because of his completely free open source, suitable for two times development, its numerous themes and plug-ins, today there are countless WordPress bloggers in the use of him, so a fatal loophole will bring tens of thousands of users of the site loss.

WordPress official previously posted on WordPress trac to repair the WordPress 2.8.x Vulnerability Information Changeset 11798, an attacker can bypass security checks through a specific URL, authenticate the user, and reset the password. The result is that the password for the first account in the database (usually the Administrator account) is reset, and a new password is e-mailed to the account owner, although others may not steal the mailbox account you used to reset the password at the same time, but the security risk is always there. Officials have fixed the problem and have been testing other possible scenarios. Or download the official latest version of WordPress2.8.4, which has fixed all known issues and strongly recommends that all WordPress users update.

Wordpress 2.8.4 English version download address: Http://wordpress.org/wordpress-2.8.4.zip

At present, WordPress 2.8.4 115.html "> Simplified Chinese version has not been released, wordpress2.8.x Chinese users can log in to the background, the point of Automatic Updates, in the background of the latest patch can fix this password loophole. With the background repair will not affect the Chinese version of the user, wordpress2.8.3 Chinese version of the demo station WWW.XRNIC.CN/CMS through the background update has been successful, the Chinese version of the upgrade is completely unaffected, we can rest assured upgrades.

Reprint please specify by wordpress2.8.3 Chinese version Demonstration Station provides, admin5.com starts. Thank you.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.