WordPress released a minor upgrade today for any blog running version 2.6. Although it’s not a huge deal, it is worth doing if your WordPress installation allows open registration. Although this isn’t necessarily a security risk, there is the possibility that a hacker could exploit a WordPress function to reset admin passwords to a randomly generated one, therefore freezing the administrator out of their website. The hacker doesn’t know the new password either, so this loophole is more of a frustration than anything else. Still, it would be a bugger if that happened, so Astroengine is now bulletproof with v2.6.2…
Once again, I used the automatic upgrade plugin created by Keith Dsouza and it performed flawlessly, backing everything up and then installing the whole lot over the top. Superb.