PHP XMLRPC Remote Code Execution Vulnerability affecting Popular Blogging and CMS Platforms like WordPress 1.5.1.2 (and lower), PostNuke, Drupal, b2evolution TikiWiki etc.July 5th, 2005 PHPXMLRPC aka XML-RPC For PHP is a PHP implementation of the XML-RPC, web RPC protocol, and was originally developed by Edd Dumbill of Useful Information Company. As of the 1.0 stable release, the project has been opened to wider involvement and moved to SourceForge.
Serious Security Vulnerabilities of WordPress 1.5.1.2 and belowJuly 5th, 2005 WordPress is a very popular personal publishing platform aka blogging platform (with a primitive CMS) in use all over the web. There are a number of serious security vulnerabilities in WordPress that may allow an attacker to ultimately run arbitrary code on the vulnerable system.
Important: Angsuman's Translator Plugin Pro & Angsuman's Translator Plugin Gold Moving...August 14th, 2008 The business of Angsuman's Translator Plugin Pro and Angsuman's Translator Plugin Gold has been transferred over to Wordpress Translator. All future news and updates on Translator Plugin Pro & Translator Plugin Gold will be available from the new site.
WordPress Patch Update From 1.5.1.2 to 1.5.1.3 Now AvailableJune 30th, 2005 WordPress developers have posted yet another "security" update. Again, as always, you have to delete everything (except wp-content/ and config.php) and re-install from scratch.
Oh No! Yet Another WordPress Fix to a Fix to a Fix to a FixMay 28th, 2005 WordPress team has come up with yet another security fix (1.5.1.2), which fixes the fix (1.5.1.1), which fixes the fix (1.5.1), which is a fix for undisclosed security defects in WordPress 1.5. Update: Now it should read: WordPress team has come up with yet another security fix (1.5.1.3) which fixes the (yet another undisclosed security risk) fix(1.5.1.2), which fixes the fix (1.5.1.1), which fixes the fix (1.5.1), which is a fix for undisclosed security defects in WordPress 1.5.
Easily Create & Manage Multiple WordPress Blogs...June 12th, 2008 Any bloggers with multiple WordPress blogs soon realizes the pain and time it costs to maintain the almost identical code base for each blogs when he has to take backups and upgrade his blogs. I was looking at various multi-blog WordPress solutions (not WordPress Mu)...
WordPress 2.0.3 ReleasedJune 1st, 2006 The new features / fixes are:
Small performance enhancements
Movable Type / Typepad importer fix
Enclosure (podcasting) fix
Bugtraq reported issue & backporting of security enhancements from 2.1 (nonces)
Misc. fixes etc....
WordPress 2.0 - The Horror Story and How to DowngradeDecember 30th, 2005 I have been hearing horror stories across the board with WordPress 2.0 release. The wordpress forum is filled with wide ranging issues.
Solving WordPress 1.5.1.2 Trackback and Pingback Sending ProblemsJune 12th, 2005 I was unable to send trackbacks and pingbacks after I tested with WordPress 1.5.1.2. I found the solution yesterday.
WordPress 2.0.2 - Time To Upgrade?March 10th, 2006 WordPress released yet another security release 2.0.2 fixing (yet again) unannounced XSS security bugs. I have not upgraded any of my blogs to 2.x release.
For "WordPress Users Only" Section StartedJuly 12th, 2005 I have started a page dedicated to WordPress users only. Here you will find links to latest WordPress plugins, news, information, tips, how-to and guidelines.
Congratulations WordPress Plugin Contest Winners & Translator Pro WinnerAugust 26th, 2007 The WordPress plugin contest results were just announced by Mark Ghosh. We sponsored a copy of Translator Pro 5.0 plugin for the competition.
Stats: Over 55.5 Million Pages Powered By WordPress...September 24th, 2007 A simple google search reveals over 55.5 million pages are generated using WordPress today. The WordPress search volume shows a healthy increase over time as can be seen from the graph.
All comments get nuked by Blackhole option on blocking open proxy lists in WordPress 1.5 (Strayhorn)March 17th, 2005 It was surprising to find no comment spam after installing WordPress 1.5, noting that I haven't enabled CAPTCHA with this upgrade. However I soon realized that I wasn't receiving any normal comments too on very commentable articles.
WordPress 2.0.4 Security Update ReleasedJuly 31st, 2006 WordPress 2.0.4 is available for download. This release contains several important security fixes, so it’s recommended upgrade for all users.
June 20th, 2005 at 11:57 pm
In my opinion, less IS more as far as software goes..
I say keep things as they are…
would love to see wordpress SEO optimized however..
June 21st, 2005 at 3:38 am
Amen to that
June 29th, 2005 at 4:12 pm
Guys,
how would you improve WP for SEO, if you could?
Just curious (’cos I happen to think it is quite good for seo as it is),
Tom
June 29th, 2005 at 9:30 pm
Yes, because there is a 1.5.3 security update coming soon. Even WP has bugs…
June 30th, 2005 at 1:53 am
@Eliott
I just created a small patch for 1.5.1.3 update for 1.5.1.2 users.
Why not patch the security issues independently of feature releases?
WP development recently has very much declined in quality. New releases are riddles with bugs and then bugfix release after release are issues. Things are breaking everywhere with even minor changes. It appears non-Object Oriented development of WordPress is finally catching up with it.
June 30th, 2005 at 6:12 am
@Tom
Mostly little things like the title of the post.
I too think WP is rather well optimized SEO wise.
July 7th, 2005 at 6:27 am
i posted some suggestions in the wordpress support forum, since the feature i am missing most, is a logical relation between posts and media data. read more here
July 7th, 2005 at 10:06 am
@parasew Can you post the link?
February 11th, 2009 at 2:44 pm
Liegts an mir oder sind bei diesem Blog die Umlaute etwas defekt? Lauter Fragezeichensymbole an der entsprechenden Stelle…
February 14th, 2009 at 7:47 am
Thanks, there is more reason to comment than ever before!
February 19th, 2009 at 11:00 am
I think there is definitely a need to upgrade in order to curb vulnerabilities. But I’m tired of having to keep up with the never-ending updradading work. :/