News for WordPress users! The next release of WordPress 2.6.2 is now available and released for your installation or upgrade, as mentioned in our previous post. According to Ryan in his blog, a critical issue that is being resolved in this version pertains to blog owners allowing open registration to the public. This was basically due to the dangers of SQL Column Truncation and weakness of mt_rand() function, as pre-warned by Stefan Esser.
Prior to this version, it is possible for anyone to create a username such that it will allow resetting another user’s password to a randomly-generated password in an open registration WordPress blog. Although not disclosed to the attacker, the problem itself is rather annoying. However, when coupled with a weakness in random number seeding in mt_rand() function, it is a security exploit as attacker is able to utilise this to predict the randomly-generated password.
Besides this, WordPress 2.6.2 also consists of several other bug fixes. All users are highly advised to upgrade to this version, for security purpose.
Download Software
WordPress 2.6.2 [tar.gz version]
WordPress 2.6.2 [zip version]