A new version of the popular blogging platform WordPress was released just a few minutes ago. It is an unexpected upgrade considering that the last WordPress update was less than two weeks ago. The new update fixes a security vulnerability that affects all but the latest version of WordPress.
This update fixes an XSS vulnerability which could be used to create comment author URLs that would redirect the system administrator away from the blog’s website to another website for security exploit. All WordPress webmasters are encouraged to update their blogs as soon as possible to patch the security vulnerability and should not ignore this update.
According to the WordPress.org site:
WordPress 2.8.2 fixes an XSS vulnerability. Comment author URLs were not fully sanitized when displayed in the admin. This could be exploited to redirect you away from the admin to another site.
Webmasters may update directly from within the WordPress admin interface or by updating manually by downloading the WordPress release from the WordPress website, then upload it to the web server and run the upgrade command manually.