<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: It&#8217;s time to upgrade WordPress</title>
	<atom:link href="http://wpgarage.com/news-views/its-time-to-upgrade-wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://wpgarage.com/news-views/its-time-to-upgrade-wordpress/</link>
	<description>wordpress tricks, hacks, and tips</description>
	<lastBuildDate>Mon, 06 Sep 2010 19:29:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Ryan</title>
		<link>http://wpgarage.com/news-views/its-time-to-upgrade-wordpress/comment-page-1/#comment-810</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Tue, 05 Feb 2008 13:52:58 +0000</pubDate>
		<guid isPermaLink="false">http://wordpressgarage.com/news-views/its-time-to-upgrade-wordpress/#comment-810</guid>
		<description>In case my interpretation is wrong ...

&quot;A flaw was found in our XML-RPC implementation such that a specially crafted request would allow any valid user to edit posts of any other user on that blog.&quot;

My impression from the above quote was that the user would need to be registered with your blog to do any damage.</description>
		<content:encoded><![CDATA[<p>In case my interpretation is wrong &#8230;</p>
<p>&#8220;A flaw was found in our XML-RPC implementation such that a specially crafted request would allow any valid user to edit posts of any other user on that blog.&#8221;</p>
<p>My impression from the above quote was that the user would need to be registered with your blog to do any damage.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://wpgarage.com/news-views/its-time-to-upgrade-wordpress/comment-page-1/#comment-809</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Tue, 05 Feb 2008 13:26:57 +0000</pubDate>
		<guid isPermaLink="false">http://wordpressgarage.com/news-views/its-time-to-upgrade-wordpress/#comment-809</guid>
		<description>Looks like 2.3.3 is upon us!

According to WordPress it is an urgent security release due to other registered users of your blog having the ability to edit any page on your blog.

http://wordpress.org/development/2008/02/wordpress-233/

Of course, if you don&#039;t allow people to register then it shouldn&#039;t matter and you won&#039;t need to upgrade - although they haven&#039;t mentioned that in the official release.</description>
		<content:encoded><![CDATA[<p>Looks like 2.3.3 is upon us!</p>
<p>According to WordPress it is an urgent security release due to other registered users of your blog having the ability to edit any page on your blog.</p>
<p><a href="http://wordpress.org/development/2008/02/wordpress-233/" rel="nofollow">http://wordpress.org/development/2008/02/wordpress-233/</a></p>
<p>Of course, if you don&#8217;t allow people to register then it shouldn&#8217;t matter and you won&#8217;t need to upgrade &#8211; although they haven&#8217;t mentioned that in the official release.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://wpgarage.com/news-views/its-time-to-upgrade-wordpress/comment-page-1/#comment-806</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Tue, 01 Jan 2008 22:48:31 +0000</pubDate>
		<guid isPermaLink="false">http://wordpressgarage.com/news-views/its-time-to-upgrade-wordpress/#comment-806</guid>
		<description>Forrest - what do you mean by &quot;compressed archive&quot;? And what makes it different from previous WordPress upgrades?</description>
		<content:encoded><![CDATA[<p>Forrest &#8211; what do you mean by &quot;compressed archive&quot;? And what makes it different from previous WordPress upgrades?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Forrest</title>
		<link>http://wpgarage.com/news-views/its-time-to-upgrade-wordpress/comment-page-1/#comment-807</link>
		<dc:creator>Forrest</dc:creator>
		<pubDate>Tue, 01 Jan 2008 19:59:27 +0000</pubDate>
		<guid isPermaLink="false">http://wordpressgarage.com/news-views/its-time-to-upgrade-wordpress/#comment-807</guid>
		<description>Sadly, this one is a compressed archive full of PHP files.  If you&#039;ve made changes to some of the core files, outside your template - like I have - this is a much more complicated upgrade than others have been...</description>
		<content:encoded><![CDATA[<p>Sadly, this one is a compressed archive full of PHP files.  If you&#8217;ve made changes to some of the core files, outside your template &#8211; like I have &#8211; this is a much more complicated upgrade than others have been&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lynne</title>
		<link>http://wpgarage.com/news-views/its-time-to-upgrade-wordpress/comment-page-1/#comment-808</link>
		<dc:creator>Lynne</dc:creator>
		<pubDate>Tue, 01 Jan 2008 17:23:29 +0000</pubDate>
		<guid isPermaLink="false">http://wordpressgarage.com/news-views/its-time-to-upgrade-wordpress/#comment-808</guid>
		<description>I&#039;m not looking forward to this, every time I try anything with this blog something goes terribly wrong!  Oh well, what choice do I have?! :-D</description>
		<content:encoded><![CDATA[<p>I&#8217;m not looking forward to this, every time I try anything with this blog something goes terribly wrong!  Oh well, what choice do I have?! <img src='http://wpgarage.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':-D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Miriam Schwab</title>
		<link>http://wpgarage.com/news-views/its-time-to-upgrade-wordpress/comment-page-1/#comment-804</link>
		<dc:creator>Miriam Schwab</dc:creator>
		<pubDate>Mon, 31 Dec 2007 07:30:47 +0000</pubDate>
		<guid isPermaLink="false">http://wordpressgarage.com/news-views/its-time-to-upgrade-wordpress/#comment-804</guid>
		<description>Ryan, that is such a good idea! But I&#039;m guessing that would cause a lot of problems for WordPress since you&#039;d have people running different versions and there would have to maybe be all sorts of branches of WordPress. But I am getting sick of upgrading for every little thing, especially when we&#039;re managing so many WordPress sites.</description>
		<content:encoded><![CDATA[<p>Ryan, that is such a good idea! But I&#8217;m guessing that would cause a lot of problems for WordPress since you&#8217;d have people running different versions and there would have to maybe be all sorts of branches of WordPress. But I am getting sick of upgrading for every little thing, especially when we&#8217;re managing so many WordPress sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://wpgarage.com/news-views/its-time-to-upgrade-wordpress/comment-page-1/#comment-805</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Sun, 30 Dec 2007 22:04:07 +0000</pubDate>
		<guid isPermaLink="false">http://wordpressgarage.com/news-views/its-time-to-upgrade-wordpress/#comment-805</guid>
		<description>Miriam - I think you meant 2.4 above, not 2.3.

The customised error template sounds like a great idea. I&#039;ve meaning to figure out how to hack that thing for a while now, but this should make it much easier.

Perhaps WordPress needs to setup a tier of upgrade levels? Perhaps green, yellow, orange and red where red means upgrade fast or your site will get hacked, orange means upgrade due to minor security problems, yellow means upgrade if you use the specific functions of WordPress which have security problems and green means there&#039;s no security updates, but upgrade if you want the extra functions they&#039;ve added.

Under that system I&#039;m assuming this latest update would be a yellow, in which case we could just go check what&#039;s wrong with our current installs and if the security problems aren&#039;t major then wait till the upgrade reaches orange, or red if we&#039;re really keen. Just an idea ...</description>
		<content:encoded><![CDATA[<p>Miriam &#8211; I think you meant 2.4 above, not 2.3.</p>
<p>The customised error template sounds like a great idea. I&#8217;ve meaning to figure out how to hack that thing for a while now, but this should make it much easier.</p>
<p>Perhaps WordPress needs to setup a tier of upgrade levels? Perhaps green, yellow, orange and red where red means upgrade fast or your site will get hacked, orange means upgrade due to minor security problems, yellow means upgrade if you use the specific functions of WordPress which have security problems and green means there&#8217;s no security updates, but upgrade if you want the extra functions they&#8217;ve added.</p>
<p>Under that system I&#8217;m assuming this latest update would be a yellow, in which case we could just go check what&#8217;s wrong with our current installs and if the security problems aren&#8217;t major then wait till the upgrade reaches orange, or red if we&#8217;re really keen. Just an idea &#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
