Journal

Archive for the 'wordpress' category.

WordPress 2.6 now available

Jul 15 | Posted by Jeffrey Barke | Add a Comment

Version 2.6 "Tyner," named for jazz pianist McCoy Tyner, contains a number of new features that make WordPress a more powerful CMS: you can now track changes to every post and page and easily post from wherever you are on the web, plus there are dozens of incremental improvements to the features introduced in version 2.5.

Read about all the updates at the WordPress blog and download 2.6 here.

Upgrading to Wordpress 2.5

Apr 9 | Posted by Jeffrey Barke | Add a Comment

Just got finished with my first Wordpress 2.5 upgrade and I'm happy to report that everything (except a !@%$#%@ spotty internet connection which made the process take at least three times at long!) went smoothly. Contrary to my expectation, none of the plugins broke!

The admin interface certainly is different—it's better, but still odd after so many years with the old one. However, I love the new one click plugin auto-upgrade feature. It downloaded, unzipped, and installed the latest version of Akismet without any problems.

Update 2008-04-06: I also like the new "modal" window approach to file upload. While the old file upload tab on the "Write Page" page was definitely usable thanks to an <iframe> and JavaScript, the interface was still a bit clunky. The new UI is definitely faster and slicker.

Update 2008-04-07: While doing another upgrade (from 2.0.9 to 2.5) I broke my first plugin: Category Visibility. However, since I'm not sure what version (other than the 2.0 series) it was last compatible with, this may not be a 2.5 issue.

Update 2008-04-07: It appears that query_posts() (or at least the way I've always used it!) is broken in 2.5. More on this to follow…

Update 2008-04-09: query_posts() is not broken, but the Adhesive plugin is.

Jeffrey Barke is senior developer and information architect at theMechanism, a maxi-media firm in New York City and London.

WordTube Exploit

May 14 | Posted by Jeffrey Barke | Add a Comment

If you're using the WordTube extension for WordPress , haven't been hacked yet, and haven't heard about the remote code execution vulnerability, then you're very lucky and should read on.

The Problem

The following critical problem affects every version of WordTube prior to 1.44. From Secunia:

M.Hasran Addahroni has reported a vulnerability in the wordTube plugin for WordPress, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

Input passed to the "wpPATH" parameter in wordtube-button.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources.

Solution

Upgrade to version 1.44 immediately!

Jeffrey Barke is senior developer and information architect at theMechanism, a maxi-media firm in New York City and London.

WordPress Plugin—Adhesive

May 10 | Posted by Jeffrey Barke | 6 comments

This plugin adds a checkbox to the post status box that lets one designate a post as "sticky." It was originally written by Owen Winkler and available at http://www.redalt.com/downloads/. Not only is it no longer available there, the latest version doesn't play well with WordPress 2.1. So I fixed it and am making Adhesive available here.

Simply follow the link below, unzip the download, and drop it into your WordPress plugins directory. Then activate it in the plugin administration panel.

Adhesive 3.3 for WordPress 2.1

Jeffrey Barke is senior developer and information architect at theMechanism, a maxi-media firm in New York City and London.

Search the Archives
Feeds

Upcoming events

  • 24 Jul 2008

O'Reilly user group program member

Add to Technorati Favorites

We endorse

Basecamp

Want to work with us yet? We’re ready when you are.