WordPress 2.6.2
Another quick heads up peeps. WordPress 2.6.2 is out and you should update ASAP - especially if you
allow registrations on your blog.
See the WordPress Dev Blog for details, but in short the new update fixes the SQL Column Truncation vulnerability and the weakness of mt_rand(). Apparently other PHP apps are vulnerable too - read the WP Dev Blog entry.
This version also fixes a bunch of new bugs. I’ll be updating in the next 24 hours and would advise you to do the same. Don’t forget to deactivate and then reactivate your plugins - and if you haven’t upgraded for a few versions, check their compatibilities.

MrCorey
:
Snuck that in there, they did! Head’s up! goes to you. Upgrading we shall go…BACK UP!!!!
[Reply]
Tuesday, 9 September 2008, 02:11 CDTSecurity is Most Important | Another Opinion Among Many:
[...] you want to upgrade your Wordpress site to version 2.6.2 to avoid an embarassing hack. Thanks to Ray for his notice of the Wordpress team’s upgrade, as I like to keep this place secure for you [...]
Tuesday, 9 September 2008, 03:17 CDTThai SEO
:
I am happy with current 2.6.1 version but Wordpress 2.6.2 contains a handful of bug fixes. I’ve just upgraded my blog to this new.
[Reply]
Tuesday, 9 September 2008, 04:09 CDTRay
:
No probs - thanks for the backlink :)
[Reply]
Tuesday, 9 September 2008, 18:17 CDTJohn from Marland Real Estate
:
Thank you for the heads up. I usually hold off on updating but it sounds like it should not procrastinate with this update. Appreciate the tip.
John@Marland Real Estate’s last blog post..Baltimore Real Estate
[Reply]
Wednesday, 10 September 2008, 01:22 CDTRingtones
:
Bad to hear that. ;( I upgraded my blogs and now gonna do it again. Anyway thanks for the info.
[Reply]
Wednesday, 10 September 2008, 03:39 CDTTen Hottest Careers
:
If I’m not allowing registration, and am satisfied, I shouldn’t be worried, correct?
[Reply]
Wednesday, 10 September 2008, 03:50 CDTMrCorey
:
Upgrading can be fairly painless, if you do it right. The instructions on the Wordpress site are quite good. There’s no worrys about upgrading if you remember to back up your site, which you should be doing regularly anyways, expecially if you’re on a shared host or one that’s new or a “no-name”, as they might not be there tomorrow (it happens) and your site will be gone.
Why not back up your site right now!
Remember, that it the upgrade request mentions the word “security” then its important and you should consider upgrading.
Then, you can upgrade Wordpress.
Here’s what I do:
1)I save my whole Wordpress install to a folder on my hard drive by downloading all of the files and folders to my computer with Filezilla - its a quick drag and drop action.
2)Once that’s done, I use cPanel’s backup utility to back up my database (this is the most important if you hose your Wordpress upgrade, you can revert back to the way it was with a database back up). This would be a mouse click in the “Backups” section of cPanel.
3)Then, I delete all of the Wordpress files, except what’s in my wp-content folder (but I have also backed that one up, just in case - that’s the only one you really need to back up).
4)I extract the new files that I got from Wordpress on my desktop (of my computer). And, then, I upload the files and folders to my site in the place of the ones I deleted, with Filezilla.
5)Then, I visit (sitename here)/wp-admin/upgrade.php to see if it needs upgrading. If it does, it will tell you and do it once you press the button. if it doesn’t, it’ll tell you and you’re done.
This will always work, unless you’ve messed with some files in wp-admin or wp-includes. if you have, then you’ve got the smarts to be able to do what I’ve described and a lot more, so upgrade.
MrCorey’s last blog post..Security is Most Important
[Reply]
Wednesday, 10 September 2008, 10:15 CDTRay
:
What Corey said :)
[Reply]
Wednesday, 10 September 2008, 18:12 CDTMacBros
:
Meh. Wordpresses Automatic upgrade is way easier than that. It’s backs everything up, downloads the files, puts you in maintenance mode, de-activates the plugins, installs new files, re-activates the plugins, and opens your site back up.
Easy peasy.
MacBros’s last blog post..All’s Clear! I Guess We’ll All Live For Now.
[Reply]
Wednesday, 10 September 2008, 23:47 CDTMrCorey
:
Good way, too, but many people never learn about that plugin (and I wanna do it myself)
MrCorey’s last blog post..Security is Most Important
[Reply]
Thursday, 11 September 2008, 01:43 CDTdrew
:
Textpattern upgrades are way easier.. it’s so secure, they have a new release about once every 6 or so months with mostly enhancements than bugs and security fixes.. you spend more time blogging than upgrading or blogging about upgrading.. ;)
[Reply]
Thursday, 11 September 2008, 01:51 CDThari
:
Like Drew, I am a fan of alternate blogging platforms. Go B2evolution :)
hari’s last blog post..Lunch breaks and effective working hours
[Reply]
Thursday, 11 September 2008, 06:12 CDTRingtones
:
hari, hehe lol!
[Reply]
Thursday, 11 September 2008, 14:43 CDTK from quickpwn gui
:
WordPress is getting a lot of flak lately for releasing these updates too soon. As far as I am concerned, I like being part of a community that keeps innovating, listening to the community and keeps giving back to them. WordPress rocks! :-)
K@quickpwn gui’s last blog post..iPhone Firmware 2.1 & iTunes 8 Windows Vista Fix Available
[Reply]
Friday, 12 September 2008, 20:23 CDTBonnie from Data Entry Services
:
I have so much to learn about WordPress and your blog help. Thanks!
[Reply]
Sunday, 14 September 2008, 19:16 CDTRika from Michigan Web Marketing Specialist
:
The bugs of the previous versions have been fixed now. This upgrade is a must do.
[Reply]
Tuesday, 16 September 2008, 12:25 CDTDJ from fashion tote bags
:
The new updates seem to work well. Thanks for the post.
[Reply]
Tuesday, 16 September 2008, 14:50 CDTTigerTom: Personal LoanShark
:
I gave up on WP a long time ago. If I want to put up a quick blog, I use ‘Simple PHP Blog’ (Go0gle it)
[Reply]
Tuesday, 16 September 2008, 15:56 CDTNick from whiplash compensation claims
:
Thanks for the heads up, only seams a week ago that I last upgraded buy better to be safe than sorry.
[Reply]
Tuesday, 16 September 2008, 16:15 CDTRay
:
Speaking of upgrades, I notice a number of you are on out of date Firefox browsers. There have been a number of updates for security reason in the last 12 months, you should be on 3.0.1.
[Reply]
Tuesday, 16 September 2008, 17:56 CDTdrew
:
Ray, if you’re gonna make the upgrade argument for Firefox, what about all the Windows users? They should upgrade to Linux to patch their huge security risks.. ;)
[Reply]
Tuesday, 16 September 2008, 19:41 CDTRay
:
I would have thought that would be a given. Notice how generous and giving I am by letting Windows users post here. All Windows users should get their patches, firewalls, virus guards, spam killers, malware killers and other assorted security tools updated stat.
Drew should run sudo slackpkg –update && sudo slackpkg –upgrade-all and I will run sudo apt-get update && sudo apt-get dist-upgrade and we’ll be fine :D
[Reply]
Tuesday, 16 September 2008, 20:16 CDTMrCorey
:
These scary insecure graphical browsers!
[Reply]
Thursday, 18 September 2008, 01:07 CDTMrCorey
:
Wow! 4 cookies just to post a comment! Plus, two just to view the page. I guess it beats the non-interactive version of the web.
MrCorey’s last blog post..Beergarita!
[Reply]
Thursday, 18 September 2008, 01:09 CDTRingtones
:
MrCorey, I experienced it too. Really great feature.
[Reply]
Thursday, 18 September 2008, 06:15 CDTRay
:
Only 4 cookies eh? I’ll have to fix that. And lol at using Lynx - I assume sftp wasn’t good enough for you then!
Ray’s last blog post..WordPress 2.6.2
[Reply]
Thursday, 18 September 2008, 09:12 CDThari
:
I now expect Ray to send me a jar of chocolate chip cookies for every comment I post here :D
hari’s last blog post..Lunch breaks and effective working hours
[Reply]
Friday, 19 September 2008, 06:19 CDTRay
:
They are on the way Hari - the postal service between our countries is terrible though :)
Ray’s last blog post..WordPress 2.6.2
[Reply]
Friday, 19 September 2008, 08:02 CDThari
:
Oh yes, the postman might eat it instead. :P
[Reply]
Friday, 19 September 2008, 12:17 CDTdrew
:
Umm.. you guys didn’t read the fine print for hosting services.. I get 35% of any cookie exchanges. You can do a whois lookup to find my home address to send them too. Failure to pay results in high chocolate chip rates and possibly chroot jail time on the server.. ;)
[Reply]
Friday, 19 September 2008, 20:15 CDTRay
:
Drew, I hear you got caught shorting marshmallows so I can believe you need the chocolate chips :)
[Reply]
Friday, 19 September 2008, 20:28 CDTdrew
:
Mmmmm… marshmellows.. :p
[Reply]
Saturday, 20 September 2008, 02:29 CDTRich from nanny cam, nanny cams, nanny cam usb, nanny cam with remote viewing, internet ready nanny cam, wireless nanny cams, spy cam, spy cams
:
Gotta say that as a fairly new user of WP, I’m luvin the Automatic Updates plugin!
[Reply]
Monday, 22 September 2008, 06:38 CDTNina from Pressure Cookers
:
I still haven’t upgraded to 2.6.2 I need a lot of time to upgrade all my sites, so I’m waiting for a 2.6.3 to take place. It’s probably just around the corner.
Nina @ Pressure Cookers´s last blog post..Philippe Richard Pressure Cooker
[Reply]
Friday, 26 September 2008, 19:55 CDTRay
:
The next one is 2.7 AFAIK. The upgrade from 2.6.x to 2.7 will be easier as most plugins should still work. You should at least install it locally so you can test your themes and plugins and get used to the differences in the dashboard and admin options.
[Reply]
Friday, 26 September 2008, 20:05 CDTKevin from Great Wall of China Facts
:
I was having so much trouble installing all of this. I just gave up and made my own website on Dreamweaver.
[Reply]
Ray
Reply:
October 11th, 2008 at 22:41 CDT
@Kevin@Great Wall of China Facts, Really? I found the install pretty simple - though that may be because Drew did all the PHP and SQL stuff on the back end for me. If you can find a decent host that supports and upgrades WordPress for you, it takes a lot of hassle out of the initial install.
[Reply]
Kurtlar Vadisi Pusu
:
I gave up on WP a long time ago.
[Reply]
Saturday, 18 October 2008, 13:49 CDTTaylor from Ascend Dreamweaver Classes
:
I would also suggest dreamweaver as an alternate to wordpress. Much more user-friendly.
[Reply]
Tuesday, 28 October 2008, 12:45 CDTRay
:
Dreamweaver? Is that suitable as a CMS or blogging platform?
Ray´s last blog post..WordPress 2.6.3
[Reply]
Tuesday, 28 October 2008, 15:33 CDTTom from Birth Of Mothra
:
I personally love WP, but it has definitely taken a lot of patience, tweaking, and trial and error. Ray - Dreamweaver is a text/code editor program. It is not a CMS or blogging platform.
Tom@Birth Of Mothra´s last blog post..Birth of Mothra - truth or fiction?
[Reply]
Ray
Reply:
October 28th, 2008 at 19:53 CDT
I know what DreamWeaver is, I was wondering if Taylor had found a way to make it do other things :) I think s/he means to write a whole site from scratch, but I could be wrong. It could just be an ad, of course……
Oh, and by the way, love the site!
[Reply]
Detektei
:
Hey, very interesting post.
My written English is not so good so I write in German:
“Lieber den Spatz in der Hand, als die Taube auf dem Dach.”
Yours sincerely
Detektei
[Reply]
Sunday, 9 November 2008, 11:41 CSTRichard E from GPS Units
:
And I just added the automatic update plugin to my blog and it works very well. So I am all updated and will stay updated. I used to update from my cPanel but there is quite a time lag before the new version migrates over there.
[Reply]
Friday, 14 November 2008, 18:20 CST