54

Wordpress 2.5.1 Security Update

Posted April 25th, 2008 by Jeremy Schoemaker

upgrade your wordpress now:

We recommend everyone update immediately, particularly if your blog has open registration. The vulnerability is not public but it will be shortly. In addition to the security fix, 2.5.1 contains over 70 bug fixes.

Disclaimer

Before acting on this post, be sure to read my Disclaimer.

- Comment Likes - Comment Dislikes

54 comments. What say you?

  1. Good Comment?
    XLOR

    Hm, not bad…guys are not sleeping.
    A week ago I got 2.5 version…now it is time to get 2.5.1…or to wait for 2.5.2 better???

  2. Good Comment?
    XLOR

    Sorry, where did you get this plugin?

  3. Good Comment?
    TEGS

    You have to stay up to date.
    Or be thrown int a pit of haxors who will have their way with your site
    menacing laugh

  4. Good Comment?
    Clive

    How can i make money i have no income at all.

  5. Good Comment?
    Prosperity Writer

    this is why i stuck with the version that best suits me

  6. Good Comment?
    stress

    i really like the very last version!

  7. Good Comment?
    Row

    Hey Shoe, you posted earlier about the issue of pre-2.33 blogs being compromised by the hijacking of the admin cookie. You recommended a *clean* install of 2.33, rather than an upgrade to 2.33.

    Fast forwarding to now, if my 2.33 blog was infected with SQL injected spam in the same way as above, should I do a *clean install* of 2.5.1, or will simply *upgrading* to 2.5.1 solve the problem?

    Thank you sire!

  8. Good Comment?
    Goran Website

    hahah, imaging if it was Microsoft. Well at least Wordpress takes responsibility and updates regularily

  9. Good Comment?
    Bahamas Hosting

    It’s nice to see the gravatar built into the 2.5 versions.

  10. Good Comment?
    Mayank Rocks

    I havent even upgraded to 2.5 yet….I am still waiting, for like dunno what lol. I think I will do it this weekend or next week….and what is this auto upgrade plugin? please help.

  11. Good Comment?
    Mayank Rocks

    I have no idea but my comments arent appearing with name “Mayank”…so I am trying back the old name “Mayank Rocks”

  12. Good Comment?
    Asia'h Epperson

    I wish I hadn’t upgraded to 2.5. I knew better. Every upgrade they come out with is followed by security and bug fixes!

  13. Good Comment?
    John

    Looks like it was already found a bug in 2.5.1. When you forget your password, ask for a new one and WP sends you a link to click. this links don’t work.

  14. Good Comment?
    Tim

    Is there an easier way to upgrade? I”ve only done it once, and it took quite a while since I don’t know what I’m going. ;-) Back up first, then delete, then reinstall, then re-import.

  15. Good Comment?
    Flimjo

    That’s the annoying bit. Fantastico is always a week or so behind the curve.

  16. Good Comment?
    Flimjo

    It seems like they come up with one every two weeks.

  17. Good Comment?
    Flimjo

    I’m not liking Wordpress 2.5 anyway. I feel like 2.3 was more user-friendly.

  18. Good Comment?
    John Chan

    But it makes slow when you post your posting. Have any body face the same problem with me?

  19. Good Comment?
    Laptop Best Buys

    Great info here, thanks!

  20. Good Comment?
    riza

    yes right, update wordpress will also increase for security blog

  21. Good Comment?
    Keith Cash

    Thanks for the heads up I will use.

  22. Good Comment?
    Web Marketeer

    Progress won’t necessarily appeal to everybody, but eventually everybody will haqve to upgrade to stay current with technology streams. Be happy that this is not a Microsoft product. Can you imagine?

  23. Good Comment?
    David Marx

    It is awesome to see the enthusiasts and users of a tool like wordpress interact and inform each other of important updates and the like. Truly viral in my opinion.

  24. Good Comment?
    jim

    Damn updates are annoying

  25. Good Comment?
    Dr. Bardou

    OMG! Do you want to say that 2.5 has 70 bugs? Is that why there is SEVENTY bug fixes in 2.5.1.?
    O_O
    Updating is the urgent case!

  26. Good Comment?
    Kevin

    In fact, it is very easy!

    Download wordpress 2.5.1
    Upload it on your web folder
    Go to /wp-login
    Press a Button
    Done!

  27. Good Comment?
    Hammad

    thanks for the update man y i upgraded to 2.5 :S i have to upgrade it again now :S

  28. Good Comment?
    Meethere

    How to do this upgrade ?
    fantastico – still not available…

  29. Good Comment?
    Terry Tay

    I just had to log on to wordpress to know about it since it says right up top when your Wordpress version needs updating, but it’s good when blogs post it I guess for those that don’t read their dashboard when they log in :-D

  30. Good Comment?
    CPA Affiliates

    wwwwwow lots of bugs got squashed with this update!

  31. Good Comment?
    Chetan

    Read about this in many other blogs too.. Will have to upgrade now!

  32. Good Comment?
    Griffology

    Update only took less then a few mins. It was painless-

  33. Good Comment?
    Nancy P Redford

    Hey I know how you guys feel with the tedium of upgrade but remember they are usually months apart and essential to keep your site secure from Malware and Hackers.

    Think of it as just another day in the life of a blogger! ;-)

  34. Good Comment?
    Clog Money

    Where is this mysterious auto update plugin you speak of? I could of course do a quick google search for this,. However it’s saturday morning I’m hungover and feeling lazy :)

  35. Good Comment?
    Michael D

    It only sucks when your installed with services like fantastico that seem to take weeks to show changes in current versions for install / upgrade.

  36. Good Comment?
    Melvin

    70 bug fixes! wow…

  37. Good Comment?
    Terry Tay

    It is simple to upgrade even without the auto upgrade plugin, although I’m not as fast as those of you who do it in 2 seconds. :-P
    ~Terry

  38. Good Comment?
    Hypnosis Dude

    Very easy upgrade, even though I upgraded manually. I’ll definately be looking into the upgrade plugin though

  39. Good Comment?
    RT

    Do you know where i can get good instructions for upgrading without fantastico?

  40. Good Comment?
    Mike1115

    Install the Auto Upgrade plugin. Press the button and upgrade.

  41. Good Comment?
    Carla Alvarez

    Thanks for the update. I caught it on your Twitter feed.

  42. Good Comment?
    Hustle Strategy

    for who? is fantastico up to date? seems most places have not updated the panel/fantastico combo if fantastico is up to date…

  43. Good Comment?
    Jason Poteet

    I heart Subversion!

  44. Good Comment?
    5.Steps.To.Improve.Your.Success

    I will update soon. I like the new version but I care about security too.

  45. Good Comment?
    Paul

    Thank you for the update.

  46. Good Comment?
    androo

    ahhh yes… and this is why I have yet to update my wordpress.. even though it takes like 2 seconds.. i shall still wait about a month more till i update.. :)

  47. Good Comment?
    Scoopdogg

    Grrr. I, too, just finished upgrading to 2.5 for all of my sites (due to hackers inserting malware into my php) and each time it took at least 20 minutes for each and I had to redo all the header and footer code and re-ftp the custom header and mess with plugins and some other crap.
    Thanks for the info.

  48. Good Comment?
    Chris Jacobson

    I upgraded to 2.5.1 in about 2 seconds like Shoe said… auto upgrade plugin FTW!

  49. Good Comment?
    Thiago Prado

    I’ll upgrade right now. How can I change the theme for WP 2.5?

  50. Good Comment?
    ShoeMoney

    it takes 2 seconds ;) not that difficult

  51. Good Comment?
    Clog Money

    I think the interface is great. I personally love to see people/organizations trying to push technological boundaries. I also think wordpress as a platform is an ideal project in which to encompass these new technologies.

  52. Good Comment?
    Clog Money

    Sigh… I literally upgraded to 2.5 yesterday. Why is that always the way?

  53. Good Comment?
    Meethere

    OMG… so many bugs.
    I should have not upgraded.
    I dont like the interface too.

Join the Discussion

*Discount rate good on new registrations only. Credits or refunds cannot be issued on previous registrations. Discount rate good through February 6, 2010, prevailing rate applies after that.