This latest release of wp-no-version will not remove the version for authenticated users. This was done to support the new WordPress update checks which alert blog owners to new versions of WordPress.

In my opinion this is really the best of both worlds, wp-scanner will not detect the version of the blog after this has been [...]

Filed Under (News, WordPress) by Philipp

A new Version of WordPress (2.3.3) is available for Download.

This release fixes one vulnerability, which allows any authenticated user access to edit any post from any user on that Blog. This is possible by sending a malicious request via the XML-RPC interface.

Replacing the xmlrpc.php file will resolve this problem: xmlrpc.php (from WP 2.3.3).

Anyway 2.3.3 fixes [...]

Lorelle discusses content theft on WordPress.com. Splogs continue to grow at a rapid rate.

Filed Under (News, WordPress) by DK

Frisco Vista’s WordPress blog ran into some security problems. His experience can be read here.

The TextLinkAds WP plugin is dynamically generated to insert the API key. I think this dynamic generation may be wrecking havoc with version numbers. I have verified this vulnerabiility in version 3.0.8.

Please do not trust the version number on your WP TextLinkAds plugin, your plugin is likely vulnerable.

The advisory has been updated accordingly.