Wordpress: Version 3.3.2 and Beta 3.4
The PHP CMS Wordpress has a new revision - 3.3.2 which is now available. Revisions include security updates to 3 external libraries:
1) PL Upload: This library is used for uploading media. The new version is at 1.5.4
2) SWF Upload: This was previously used for uploading media, and still available to use
3) SWF Object: This was previously used to embed Flash content, and is still available to use
Wordpress 3.3.2 also comes with revisions to a few problems that had been encountered by the community:
1) Privilege escalation has been addressed
2) Clickable URLs (which had cross site scripting vulnerabilities) has been addressed
3) Older browsers were vulnerable to cross site scripting in redirects after posting comments. Fseiltering URLs has also been addressed
Version 3.4 Beta 1 can now be downloaded and tested - the full version is scheduled for release in May. Some of the new features to look forward to include:
1) Customisable themes and preview capability
2) Custom headers now have more flexibility
3) Custom header and background images can be selected via the Media library
4) Improved theme search and selection
Other new improvements include enhancements to WP_Query, internationalisation and external/mobile application APIs. Bugs can be reported to the Forum and Emailed to the Testers list. Happy testing!