WordPress Upgrade – 1.5.1.3 and Security Issues

Remote procedure calls (RPC) are the subject of this new update to 1.5.1.3. The xmlrpc.php file has major changes to prevent a security problem.

Remote procedure calls can be used as a remote control on your site, and is used to publish from a distance. It can also be misused, which explains this security update.

From 1.5.1.2, the list of changed files is as follows:

Significant/Major Changes
xmlrpc.php
wp-admin/post.php
wp-includes/functions-post.php

Cosmetic/Minor Changes
wp-includes/version.php
wp-login.php
readme.html

On the bright side, there appears to be no db upgrade, so you should be able to drop the five files onto your blog (readme.html isn’t needed) and be good to go (if you’re already at 1.5.1.2, that is).

Check out the WordPress site for further/late breaking news.

Comments are closed.