View Single Post
  #3 (permalink)  
Old 05-18-2009, 02:15 AM
Ceres's Avatar
Ceres Ceres is offline
Senior Member
 
Join Date: Mar 2008
Location: Canada
Posts: 2,206
iTrader: (0)
Thanks: 544
Thanked 572 Times in 345 Posts
Ceres is a splendid one to beholdCeres is a splendid one to beholdCeres is a splendid one to beholdCeres is a splendid one to beholdCeres is a splendid one to beholdCeres is a splendid one to beholdCeres is a splendid one to behold
Default Re: WordPress 2.8 Will Be Released in May

Quote:
Originally Posted by Jeff View Post
Are there any security issues with the current release?
Currently, there are no security issues reported on the WordPress site.

However, I just came across a blog post on Perishable Press that talks about an important security fix for WordPress. The writer explains that if your server crashes, WordPress sometimes display the WordPress Installation Page to your visitors. This can possibly allow hackers to take control of your website.

You will see from the comments that some people think the displayed Installation Page is not a major security risk, while others think it is. What are your views?

I don't think it's a risk I want to take, and therefore we should delete/block/modify the wp-admin/install.php file as suggested by Perishable Press.
Reply With Quote