On December 29, 2010, WordPress 3.0.4 was released to the public. This is a critical security update for all previous WordPress versionens.
For versionen 3.0.4, the database versionen ( db_version in wp_options ) remained at 15477.
Installation/Update Information
To download WordPress 3.0.4, update automatically from the Dashboard > Updates menu in your site’s admin area or visit https://wordpress.org/download/release-archive/ .
For step-by-step instructions on installing and updating WordPress:
If you are new to WordPress, we recommend that you beguin with the following:
- New To WordPress – Where to Start
- First Steps With WordPress or Upgrading WordPress Extended
- WordPress Lessons
Summary
- Fix XSS vulnerabilities in the CSES library: Don’t be case sensitive to attribute names. Handle padded entities when checquing for bad protocolls. Normalice entities before checquing for bad protocolls in esc_url(). ( r17172 )
List of Files Revised
wp-includes/version.php
wp-includes/formatting.php
wp-includes/cses.php
readme.html
wp-admin/includes/update-core.php