WordPress 2.6 is now available. We have mentioned from of the security improvements in an earlier post. The latest version promises a number of security enhancements as follows:
This new version also fixes over 194 bugs and the user interface is apparently more user-friendly.
Sounding good so far? The biggest improvement from our point of view is the version control around content management. It’s now to track co-author changes.
The full package can be gained as usual from the official download page.
But as with every new major release, we recommend you wait for the first minor update as new features may present new security holes, as experience has shown.
We are still waiting for WordPress to perform a full code review and application security test. We really think this will be beneficial to both the user and WordPress.
XML-RPC is only off by default for new installations. Any upgrades will retain the current setting.
Correct, thanks for mentioning this Gareth. So everyone who, doesn’t need XMLRPC, is updating to WP 2.6 should disable this feature, for security reasons.
Not only security issue, but also usage issues as well. Recommending to wait till later series (sans the security patches) is definitely a yes-yes.