今天Wordpress发布了3.5.2版本,应该只是「增加了稳定性」的小更新
更新内容
这是Wordpress官网列出的更新内容:(我懒的翻译 :mrgreen:)
* Server-Side Request Forgery (SSRF) via the HTTP API. CVE-2013-2199.
* Privilege Escalation: Contributors can publish posts, and users can reassign authorship. CVE-2013-2200.
* Cross-Site Scripting (XSS) in SWFUpload. CVE-2013-2205.
* Denial of Service (DoS) via Post Password Cookies. CVE-2013-2173.
* Content Spoofing via Flash Applet in TinyMCE Media Plugin. CVE-2013-2204.
* Cross-Site Scripting (XSS) when Uploading Media. CVE-2013-2201.
* Full Path Disclosure (FPD) during File Upload. CVE-2013-2203.
* Cross-Site Scripting (XSS) (Low Severity) when Editing Media. CVE-2013-2201.
* Cross-Site Scripting (XSS) (Low Severity) when Installing/Updating Plugins/Themes. CVE-2013-2201.
* XML External Entity Injection (XXE) via oEmbed. CVE-2013-2202.
总结
1、现在(2013年6月22日)还只有英文版,我还是等著正体中文出来在更新
2013年6月24日更新:Wordpress 3.5.2 繁體中文版本已经发布(本站已经更新)
2、希望Wordpress 3.6快点完成