- Atom feed validation fixes (#4274, #4307, #4381, #4382)
- XML-RPC fixes (#4314, #4329, #4315, #4469)
- Widget backward compatibility fixes (#4275)
- Widget layout fixes for IE7 (#4264, #4268)
- Page and Text Widget improvements (#4302, #4259)
Unfortunately, 2.2.1 is not just a bug fix release. Some security issues came to light during 2.2.1 development, making 2.2.1 a required upgrade. 2.2.1 addresses the following vulnerabilities:
- Remote shell injection in PHPMailer
- Remote SQL injection in XML-RPC Discovered by Alexander Concha.
- Unescaped attribute in default theme
Special thanks to Alexander Concha for his continued assistance in making WordPress more secure. Special thanks also to Daniel Jalkut of Red Sweater Software for his improvements to our XML-RPC implementation.







Leave a reply