WordPress 2.6.2

Another quick heads up peeps.  WordPress 2.6.2 is out and you should update ASAP - especially if you

WordPress.org

WordPress.org

allow registrations on your blog.

See the WordPress Dev Blog for details, but in short the new update fixes the SQL Column Truncation vulnerability and the weakness of mt_rand().  Apparently other PHP apps are vulnerable too - read the WP Dev Blog entry.

This version also fixes a bunch of new bugs.  I’ll be updating in the next 24 hours and would advise you to do the same.  Don’t forget to deactivate and then reactivate your plugins - and if you haven’t upgraded for a few versions, check their compatibilities.

45 Comments

  1. MrCoreyNo Gravatar:

    Snuck that in there, they did! Head’s up! goes to you. Upgrading we shall go…BACK UP!!!!

    [Reply]

  2. Security is Most Important | Another Opinion Among Many:

    [...] you want to upgrade your Wordpress site to version 2.6.2 to avoid an embarassing hack.  Thanks to Ray for his notice of the Wordpress team’s upgrade, as I like to keep this place secure for you [...]

  3. Thai SEONo Gravatar:

    I am happy with current 2.6.1 version but Wordpress 2.6.2 contains a handful of bug fixes. I’ve just upgraded my blog to this new.

    [Reply]

  4. RayNo Gravatar:

    No probs - thanks for the backlink :)

    [Reply]

  5. John from Marland Real EstateNo Gravatar:

    Thank you for the heads up. I usually hold off on updating but it sounds like it should not procrastinate with this update. Appreciate the tip.

    John@Marland Real Estate’s last blog post..Baltimore Real Estate

    [Reply]

  6. RingtonesNo Gravatar:

    Bad to hear that. ;( I upgraded my blogs and now gonna do it again. Anyway thanks for the info.

    [Reply]

  7. Ten Hottest CareersNo Gravatar:

    If I’m not allowing registration, and am satisfied, I shouldn’t be worried, correct?

    [Reply]

  8. MrCoreyNo Gravatar:

    Upgrading can be fairly painless, if you do it right. The instructions on the Wordpress site are quite good. There’s no worrys about upgrading if you remember to back up your site, which you should be doing regularly anyways, expecially if you’re on a shared host or one that’s new or a “no-name”, as they might not be there tomorrow (it happens) and your site will be gone.

    Why not back up your site right now!

    Remember, that it the upgrade request mentions the word “security” then its important and you should consider upgrading.

    Then, you can upgrade Wordpress.

    Here’s what I do:

    1)I save my whole Wordpress install to a folder on my hard drive by downloading all of the files and folders to my computer with Filezilla - its a quick drag and drop action.

    2)Once that’s done, I use cPanel’s backup utility to back up my database (this is the most important if you hose your Wordpress upgrade, you can revert back to the way it was with a database back up). This would be a mouse click in the “Backups” section of cPanel.

    3)Then, I delete all of the Wordpress files, except what’s in my wp-content folder (but I have also backed that one up, just in case - that’s the only one you really need to back up).

    4)I extract the new files that I got from Wordpress on my desktop (of my computer). And, then, I upload the files and folders to my site in the place of the ones I deleted, with Filezilla.

    5)Then, I visit (sitename here)/wp-admin/upgrade.php to see if it needs upgrading. If it does, it will tell you and do it once you press the button. if it doesn’t, it’ll tell you and you’re done.

    This will always work, unless you’ve messed with some files in wp-admin or wp-includes. if you have, then you’ve got the smarts to be able to do what I’ve described and a lot more, so upgrade.

    MrCorey’s last blog post..Security is Most Important

    [Reply]

  9. MacBrosNo Gravatar:

    Meh. Wordpresses Automatic upgrade is way easier than that. It’s backs everything up, downloads the files, puts you in maintenance mode, de-activates the plugins, installs new files, re-activates the plugins, and opens your site back up.

    Easy peasy.

    MacBros’s last blog post..All’s Clear! I Guess We’ll All Live For Now.

    [Reply]

  10. MrCoreyNo Gravatar:

    Good way, too, but many people never learn about that plugin (and I wanna do it myself)

    MrCorey’s last blog post..Security is Most Important

    [Reply]

  11. drewNo Gravatar:

    Textpattern upgrades are way easier.. it’s so secure, they have a new release about once every 6 or so months with mostly enhancements than bugs and security fixes.. you spend more time blogging than upgrading or blogging about upgrading.. ;)

    [Reply]

  12. hariNo Gravatar:

    Like Drew, I am a fan of alternate blogging platforms. Go B2evolution :)

    hari’s last blog post..Lunch breaks and effective working hours

    [Reply]

  13. K from quickpwn guiNo Gravatar:

    WordPress is getting a lot of flak lately for releasing these updates too soon. As far as I am concerned, I like being part of a community that keeps innovating, listening to the community and keeps giving back to them. WordPress rocks! :-)

    K@quickpwn gui’s last blog post..iPhone Firmware 2.1 & iTunes 8 Windows Vista Fix Available

    [Reply]

  14. Bonnie from Data Entry ServicesNo Gravatar:

    I have so much to learn about WordPress and your blog help. Thanks!

    [Reply]

  15. Rika from Michigan Web Marketing SpecialistNo Gravatar:

    The bugs of the previous versions have been fixed now. This upgrade is a must do.

    [Reply]

  16. DJ from fashion tote bagsNo Gravatar:

    The new updates seem to work well. Thanks for the post.

    [Reply]

  17. TigerTom: Personal LoanSharkNo Gravatar:

    I gave up on WP a long time ago. If I want to put up a quick blog, I use ‘Simple PHP Blog’ (Go0gle it)

    [Reply]

  18. Nick from whiplash compensation claimsNo Gravatar:

    Thanks for the heads up, only seams a week ago that I last upgraded buy better to be safe than sorry.

    [Reply]

  19. RayNo Gravatar:

    Speaking of upgrades, I notice a number of you are on out of date Firefox browsers. There have been a number of updates for security reason in the last 12 months, you should be on 3.0.1.

    [Reply]

  20. drewNo Gravatar:

    Ray, if you’re gonna make the upgrade argument for Firefox, what about all the Windows users? They should upgrade to Linux to patch their huge security risks.. ;)

    [Reply]

  21. RayNo Gravatar:

    I would have thought that would be a given. Notice how generous and giving I am by letting Windows users post here. All Windows users should get their patches, firewalls, virus guards, spam killers, malware killers and other assorted security tools updated stat.

    Drew should run sudo slackpkg –update && sudo slackpkg –upgrade-all and I will run sudo apt-get update && sudo apt-get dist-upgrade and we’ll be fine :D

    [Reply]

  22. MrCoreyNo Gravatar:

    These scary insecure graphical browsers!

    [Reply]

  23. MrCoreyNo Gravatar:

    Wow! 4 cookies just to post a comment! Plus, two just to view the page. I guess it beats the non-interactive version of the web.

    MrCorey’s last blog post..Beergarita!

    [Reply]

  24. RingtonesNo Gravatar:

    MrCorey, I experienced it too. Really great feature.

    [Reply]

  25. RayNo Gravatar:

    Only 4 cookies eh? I’ll have to fix that. And lol at using Lynx - I assume sftp wasn’t good enough for you then!

    Ray’s last blog post..WordPress 2.6.2

    [Reply]

  26. hariNo Gravatar:

    I now expect Ray to send me a jar of chocolate chip cookies for every comment I post here :D

    hari’s last blog post..Lunch breaks and effective working hours

    [Reply]

  27. RayNo Gravatar:

    They are on the way Hari - the postal service between our countries is terrible though :)

    Ray’s last blog post..WordPress 2.6.2

    [Reply]

  28. hariNo Gravatar:

    Oh yes, the postman might eat it instead. :P

    [Reply]

  29. drewNo Gravatar:

    Umm.. you guys didn’t read the fine print for hosting services.. I get 35% of any cookie exchanges. You can do a whois lookup to find my home address to send them too. Failure to pay results in high chocolate chip rates and possibly chroot jail time on the server.. ;)

    [Reply]

  30. RayNo Gravatar:

    Drew, I hear you got caught shorting marshmallows so I can believe you need the chocolate chips :)

    [Reply]

  31. drewNo Gravatar:

    Mmmmm… marshmellows.. :p

    [Reply]

  32. Nina from Pressure CookersNo Gravatar:

    I still haven’t upgraded to 2.6.2 I need a lot of time to upgrade all my sites, so I’m waiting for a 2.6.3 to take place. It’s probably just around the corner.

    Nina @ Pressure Cookers´s last blog post..Philippe Richard Pressure Cooker

    [Reply]

  33. RayNo Gravatar:

    The next one is 2.7 AFAIK. The upgrade from 2.6.x to 2.7 will be easier as most plugins should still work. You should at least install it locally so you can test your themes and plugins and get used to the differences in the dashboard and admin options.

    [Reply]

  34. Kevin from Great Wall of China FactsNo Gravatar:

    I was having so much trouble installing all of this. I just gave up and made my own website on Dreamweaver.

    [Reply]

    RayNo Gravatar Reply:

    @Kevin@Great Wall of China Facts, Really? I found the install pretty simple - though that may be because Drew did all the PHP and SQL stuff on the back end for me. If you can find a decent host that supports and upgrades WordPress for you, it takes a lot of hassle out of the initial install.

    [Reply]

  35. Kurtlar Vadisi PusuNo Gravatar:

    I gave up on WP a long time ago.

    [Reply]

  36. Taylor from Ascend Dreamweaver ClassesNo Gravatar:

    I would also suggest dreamweaver as an alternate to wordpress. Much more user-friendly.

    [Reply]

  37. RayNo Gravatar:

    Dreamweaver? Is that suitable as a CMS or blogging platform?

    Ray´s last blog post..WordPress 2.6.3

    [Reply]

  38. Tom from Birth Of MothraNo Gravatar:

    I personally love WP, but it has definitely taken a lot of patience, tweaking, and trial and error. Ray - Dreamweaver is a text/code editor program. It is not a CMS or blogging platform.

    Tom@Birth Of Mothra´s last blog post..Birth of Mothra - truth or fiction?

    [Reply]

    RayNo Gravatar Reply:

    I know what DreamWeaver is, I was wondering if Taylor had found a way to make it do other things :) I think s/he means to write a whole site from scratch, but I could be wrong. It could just be an ad, of course……

    Oh, and by the way, love the site!

    [Reply]

  39. DetekteiNo Gravatar:

    Hey, very interesting post.

    My written English is not so good so I write in German:

    “Lieber den Spatz in der Hand, als die Taube auf dem Dach.”

    Yours sincerely
    Detektei

    [Reply]

  40. Richard E from GPS UnitsNo Gravatar:

    And I just added the automatic update plugin to my blog and it works very well. So I am all updated and will stay updated. I used to update from my cPanel but there is quite a time lag before the new version migrates over there.

    [Reply]

Leave a comment

This site uses KeywordLuv. Enter YourName@YourKeywords in the Name field to take advantage.