今天Wordpress發佈了3.5.2版本,應該只是「增加了穩定性」的小更新
更新內容
這是Wordpress官網列出的更新內容:(我懶的翻譯 :mrgreen:)
* Server-Side Request Forgery (SSRF) via the HTTP API. CVE-2013-2199.
* Privilege Escalation: Contributors can publish posts, and users can reassign authorship. CVE-2013-2200.
* Cross-Site Scripting (XSS) in SWFUpload. CVE-2013-2205.
* Denial of Service (DoS) via Post Password Cookies. CVE-2013-2173.
* Content Spoofing via Flash Applet in TinyMCE Media Plugin. CVE-2013-2204.
* Cross-Site Scripting (XSS) when Uploading Media. CVE-2013-2201.
* Full Path Disclosure (FPD) during File Upload. CVE-2013-2203.
* Cross-Site Scripting (XSS) (Low Severity) when Editing Media. CVE-2013-2201.
* Cross-Site Scripting (XSS) (Low Severity) when Installing/Updating Plugins/Themes. CVE-2013-2201.
* XML External Entity Injection (XXE) via oEmbed. CVE-2013-2202.
總結
1、現在(2013年6月22日)還只有英文版,我還是等著正體中文出來在更新
2013年6月24日更新:Wordpress 3.5.2 繁體中文版本已經發佈(本站已經更新)
2、希望Wordpress 3.6快點完成