summaryrefslogtreecommitdiff
path: root/www/wordpress
AgeCommit message (Collapse)AuthorFilesLines
2017-09-21Security update to version 4.8.2morr2-7/+7
Security issues: - $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi). WordPress core is not directly vulnerable to this issue, but we’ve added hardening to prevent plugins and themes from accidentally causing a vulnerability. Reported by Slavco. - A cross-site scripting (XSS) vulnerability was discovered in the oEmbed discovery. Reported by xknown of the WordPress Security Team. - A cross-site scripting (XSS) vulnerability was discovered in the visual editor. Reported by Rodolfo Assis (@brutelogic) of Sucuri Security. - A path traversal vulnerability was discovered in the file unzipping code. Reported by Alex Chapman (noxrnet). - A cross-site scripting (XSS) vulnerability was discovered in the plugin editor. Reported by 陈瑞琦 (Chen Ruiqi). - An open redirect was discovered on the user and term edit screens. Reported by Yasin Soliman (ysx). - A path traversal vulnerability was discovered in the customizer. Reported by Weston Ruter of the WordPress Security Team. - A cross-site scripting (XSS) vulnerability was discovered in template names. Reported by Luka (sikic). - A cross-site scripting (XSS) vulnerability was discovered in the link modal. Reported by Anas Roubi (qasuar). And 6 other fixes: * Emoji - #41584 - Upgrade Twemoji to 2.5.0 - #41852 - Fix UN flag test by returning the correct value. *I18N - #41794 - Support numbers in locales during installation * Security - #13377 - Add more sanitization in _cleanup_header_comment *Widgets - #41596 - New Text Widget recognizes HTML but does not render it in the front end - #41622 - Text widget can show DOMDocument::loadHTML() warnings in admin when is_legacy_widget method is called More on https://codex.wordpress.org/Version_4.8.2
2017-09-06Follow some redirects.wiz1-3/+3
2017-08-07Update to version 4.8.1.morr2-7/+7
WordPress 4.8.1 contains 29 maintenance fixes and enhancements to the 4.8 release series, chief among them are fixes to the rich Text widget and the introduction of the Custom HTML widget. Administration * #40982 - Permalink Settings: custom structure field keyboard trap Build/Test Tools * #41327 - Bump Akismet External - 4.9 Edition Comments * #40975 - 'Empty Spam' and 'Empty Trash' comment buttons not displayed on mobile Customize * #40978 - Customizer Panel Footer border missing * #40981 - Customizer: Menus: it is far too easy to mistakenly delete a menu because the "Delete Menu" link and the "Add Items" button are too close together * #41158 - Increase tinymce panel z-index * #41410 - Set `'filter' => 'content'` on starter content "business info" widget Embeds * #41019 - oEmbed: Update VideoPress oEmbed URL * #41048 - `WP_oEmbed_Controller::get_proxy_item()` should remove `_wpnonce` from cached `$args` * #41299 - oEmbed proxy fails to forward maxwidth and maxheight params General * #41056 - WP-API JS Client: Settings is incorrectly registered as a collection Media * #41231 - media-views.js: Cannot read .length of undefined (this.controller.$uploaderToggler.length) REST API * #38964 - Add filter to allow modifying response *after* embedded data is added * #40886 - REST API: PUT requests fail on Nginx servers when fancy permalinks aren't enabled Taxonomy * #41010 - wp_get_object_terms() returns duplicate terms if more than one taxonomy is given in args TinyMCE * #41408 - TinyMCE: Images with link and caption look "broken" when selected Widgets * #40907 - Introduce widget dedicated for HTML code * #40935 - Facebook Video Works On Preview But Not On Theme * #40951 - New Text Widget - Switching Between Visual/Text Editor Strips Out Code * #40960 - Widgets: The Text widget should respect the “Disable the visual editor when writing” setting * #40972 - TinyMCE editor in Text widget does not have RTL contents * #40974 - Updated text widget do not save text (when using paste) * #40977 - Widgets: Query param for `loop` added for non-hosted external videos * #40986 - Widgets: text widget and media widgets cannot be edited in accessibility mode * #41021 - Text widget does not show Title field or TinyMCE editor * #41361 - Text widget can raise JS error if customize-base is enqueued on widgets admin screen * #41386 - Text Widget - Wording - Legacy Mode 4.8.1 beta * #41392 - Theme styles for Text widget do not apply to Custom HTML widget * #41394 - Text widget: Rename legacy mode to visual mode and improve back-compat for widget_text filters
2017-06-18Update to newest version 4.8.morr3-16/+23
For changes, check https://codex.wordpress.org/Version_4.8.
2017-05-30Security update 4.7.5. Bugs fixed:jklos2-8/+8
Insufficient redirect validation in the HTTP class. Reported by Ronni Skansing. Improper handling of post meta data values in the XML-RPC API. Reported by Sam Thomas. Lack of capability checks for post meta data in the XML-RPC API. Reported by Ben Bidner of the WordPress Security Team. A Cross Site Request Forgery (CSRF) vulnerability was discovered in the filesystem credentials dialog. Reported by Yorick Koster. A cross-site scripting (XSS) vulnerability was discovered when attempting to upload very large files. Reported by Ronni Skansing. A cross-site scripting (XSS) vulnerability was discovered related to the Customizer. Reported by Weston Ruter of the WordPress Security Team.
2017-04-15PKGREVISION was too high, 1 is enough.taca1-2/+2
2017-04-15Switch to use php-mysqli.taca1-3/+3
Bump PKGREVISION.
2017-04-15WordPress 4.7 suggests using PHP 7, so remove PHP's version restriction totaca1-2/+1
56 now.
2017-03-12pkgrevision bump for changed apache default.maya1-1/+2
bumping any package depending on a pkg with APACHE_PKG_PREFIX but without APACHE_PKG_PREFIX in its PKGNAME.
2017-03-07Security update to version 4.7.3.morr3-9/+8
Fixed security bugs: * Cross-site scripting (XSS) via media file metadata. Reported by Chris Andrè Dale, Yorick Koster, and Simon P. Briggs. * Control characters can trick redirect URL validation. Reported by Daniel Chatfield. * Unintended files can be deleted by administrators using the plugin deletion functionality. Reported by xuliang. * Cross-site scripting (XSS) via video URL in YouTube embeds. Reported by Marc Montpas. * Cross-site scripting (XSS) via taxonomy term names. Reported by Delta. * Cross-site request forgery (CSRF) in Press This leading to excessive use of server resources. Reported by Sipke Mellema. More information here: https://codex.wordpress.org/Version_4.7.3
2017-01-28Security update to version 4.7.2.morr2-7/+7
Changes: Version 4.7.2 * Remote code execution (RCE) in PHPMailer – No specific issue appears to affect WordPress or any of the major plugins we investigated but, out of an abundance of caution, we updated PHPMailer in this release. This issue was reported to PHPMailer by Dawid Golunski and Paul Buonopane. * The REST API exposed user data for all users who had authored a post of a public post type. WordPress 4.7.1 limits this to only post types which have specified that they should be shown within the REST API. Reported by Krogsgard and Chris Jean. * Cross-site scripting (XSS) via the plugin name or version header on update-core.php. Reported by Dominik Schilling of the WordPress Security Team. * Cross-site request forgery (CSRF) bypass via uploading a Flash file. Reported by Abdullah Hussam. * Cross-site scripting (XSS) via theme name fallback. Reported by Mehmet Ince. * Post via email checks mail.example.com if default settings aren’t changed. Reported by John Blackbourn of the WordPress Security Team. * A cross-site request forgery (CSRF) was discovered in the accessibility mode of widget editing. Reported by Ronnie Skansing. * Weak cryptographic security for multisite activation key. Reported by Jack. Version 4.7.1 * The user interface for assigning taxonomy terms in Press This is shown to users who do not have permissions to use it. Reported by David Herrera of Alley Interactive. * WP_Query is vulnerable to a SQL injection (SQLi) when passing unsafe data. WordPress core is not directly vulnerable to this issue, but we’ve added hardening to prevent plugins and themes from accidentally causing a vulnerability. Reported by Mo Jangda (batmoo). * A cross-site scripting (XSS) vulnerability was discovered in the posts list table. Reported by Ian Dunn of the WordPress Security Team.
2017-01-09Update to newest version 4.7.morr3-69/+116
Major changes: New Default Theme - Twenty Seventeen - It is an ambitious theme designed for business websites that focuses on a creative home page and an easy site setup experience for users. * multiple sections on the front page, selected in the Customizer. * a striking asymmetrical grid. * custom color schemes, built on top of a monochromatic foundation, and adjustable via a hue picker. * different headline placement for pages, changeable in the Customizer, via them options. * a great experience in many languages, thanks to language-specific font stacks. * SVG icons (a first for a default theme). * support for custom logo, custom header image and many post formats. * the use of new functions in Core for making child theming easier. Note: Twenty Seventeen only works on 4.7 and above. It uses the new video header and starter content features, each launched in 4.7. REST API Content Endpoints * API endpoints for WordPress content. WordPress 4.7 comes with REST API endpoints for posts, comments, terms, users, meta, and settings. Content endpoints provide machine-readable external access to your WordPress site with a clear, standards-driven interface, paving the way for new and innovative methods of interacting with your site.
2016-09-29Security update to version 4.6.1.morr3-9/+9
WordPress versions 4.6 and earlier are affected by two security issues: a cross-site scripting vulnerability via image filename, reported by SumOfPwn researcher Cengiz Han Sahin; and a path traversal vulnerability in the upgrade package uploader, reported by Dominik Schilling from the WordPress security team. WordPress 4.6.1 also fixes 15 bugs from Version 4.6, including: Bootstrap/Load #37680 – PHP Warning: ini_get_all() has been disabled for security reasons - Database #37683 – $collate and $charset can be undefined in wpdb::init_charset() #37689 – Issues with utf8mb4 collation and the 4.6 update - Editor #37690 – Backspace causes jumping - Email #37736 – Emails fail on certain server setups - External Libraries #37700 – Warning: curl_exec() has been disabled for security reasons (Requests library) #37720 – The minified version of the Masonry shim was not updated in #37666 (Masonry library) - HTTP API #37733 – cURL error 3: malformed for remote requests #37768 – HTTP API no longer accepts integer and float values for the cookies argument - Post Thumbnails #37697 – Strange behavior with thumbnails on preview in 4.6 - Script Loader #37800 – Close “link rel” dns-prefetch tag - Taxonomy #37721 – Improve error handling of is_object_in_term in taxonomy.php - Themes #37755 – Visual Editor: Weird unicode (Vietnamese) characters display on WordPress 4.6 - TinyMCE #37760 – Problem with RTL - Upgrade/Install #37731 – Infinite loop in _wp_json_sanity_check() during plugin install
2016-08-22Bump revision for previous commitmorr1-1/+2
2016-08-22pkgsrc changes to package:morr4-16/+38
- Add missing php modules - Limit work with php-5.6 - Improve the wordpress.conf - Install wp-config-sample.php to WPHOME but not EGDIR Patch from wen heping.
2016-08-21Update WordPress to 4.6 "Pepper":jklos3-11/+94
https://wordpress.org/news/2016/08/pepper/
2016-06-22Update WordPress to 4.5.3. This is a maintenance and security release:jklos2-7/+7
https://wordpress.org/news/2016/06/wordpress-4-5-3/
2016-05-04Update to newest version of 4.5.1.morr3-9/+59
For 4.5.1 This maintenance release fixes a total of 12 bugs in Version 4.5 including: Build/Test Tools #36498 Shrinkwrap npm dependencies for 4.5 Bundled Theme #36510 Twenty eleven page templates with widgets incorrectly styled Customize #36457 Customizer Device Preview: Use px units for tablet preview size Database #36629 Database connect functions can cause un-catchable warnings Editor #36458 Fix support for Safari + VoiceOver when editing inline links Emoji #36604 Emoji skin tone support test incorrectly passing in Chrome Feeds #36620 Feeds using an rss-http content type are now served as application/octet-stream Media #36501 Fatal error: Undefined class constant 'ALPHACHANNEL_UNDEFINED' #36578 wp_ajax_send_attachment_to_editor() bug #36621 Don’t cache the results of wp_mkdir_p() in a persistent cache Rewrite Rules #36506 Duplicate directives in web.config after WordPress 4.5 installation on Windows TinyMCE #36545 WordPress TinyMCE toolbar/tabs unresponsive in Chrome Version 50.0.2661.75 beta-m (64-bit) For 4.5. What's New Security - SSRF Bypass using Octal & Hexedecimal IP addresses, reported by Yu Wang & Tong Shi from BAIDU XTeam - Reflected XSS on the network settings page, reported by Emanuel Bronshtein (@e3amn2l) - Script compression option CSRF, reported by Ronni Skansing Posts - Inline Link Editing - Additional Editor Shortcuts Comments - Moderate Comment Screen Refresh - Max Lengths for Comment Form Fields - Comment Error Page Navigation Appearance - Responsive Preview of your site - Theme Logo Support - Selective Refresh - Easy of use Install Process Version 4.5 default to generating secret keys and salts locally instead of relying on the WordPress.org API Detail can be found here: http://codex.wordpress.org/Version_4.5 http://codex.wordpress.org/Version_4.5.1
2016-02-11Update Wordpress to 4.4.2.jklos2-7/+7
2016-01-03Update to newest version 4.4.morr3-72/+159
What's New General * Developer reference - Improvements to inline code documentation. * i18n support - Improvements to translation strings all over the core. * Admin page headings were adjusted from H3 to H2 tags to reinforce page hierarchy * Improvements to how list tables are displayed on all size screens Posts * The post/page permalink UI was simplified, linking the permalink and removing the "View" button Comments * The "View Comment" link was relocated from the Status meta box in the comment-editing screen * Many comment functions can now accept a full object instead of 'comment_ID' to reduce cache/db lookups * Orphaned comments now fall back to the 'edit_posts' capability Appearance * Site icons will now fall back to the 'full' size URL when the 'thumbnail' size doesn't exist Multisite * The language chooser was added to the new site form on wp-signup.php * Sites may no longer be created with the following reserved slugs: wp-admin, wp-content, wp-includes, or wp-json
2015-12-06Explicitly restrict PHP_VERSIONS_ACCEPTED to 55 and 56 for packages whichtaca1-1/+3
use php-mysql package.
2015-11-04Add SHA512 digests for distfiles for www categoryagc1-1/+2
Problems found locating distfiles: Package haskell-cgi: missing distfile haskell-cgi-20001206.tar.gz Package nginx: missing distfile array-var-nginx-module-0.04.tar.gz Package nginx: missing distfile encrypted-session-nginx-module-0.04.tar.gz Package nginx: missing distfile headers-more-nginx-module-0.261.tar.gz Package nginx: missing distfile nginx_http_push_module-0.692.tar.gz Package nginx: missing distfile set-misc-nginx-module-0.29.tar.gz Package nginx-devel: missing distfile echo-nginx-module-0.58.tar.gz Package nginx-devel: missing distfile form-input-nginx-module-0.11.tar.gz Package nginx-devel: missing distfile lua-nginx-module-0.9.16.tar.gz Package nginx-devel: missing distfile nginx_http_push_module-0.692.tar.gz Package nginx-devel: missing distfile set-misc-nginx-module-0.29.tar.gz Package php-owncloud: missing distfile owncloud-8.2.0.tar.bz2 Otherwise, existing SHA1 digests verified and found to be the same on the machine holding the existing distfiles (morden). All existing SHA1 digests retained for now as an audit trail.
2015-09-17Security update to version 4.3.1.morr2-6/+6
This version fixes two cross-site scripting vulnerabilities (CVE-2015-5714, CVE-2015-5715) and a potential privilege escalation.
2015-08-21Update WordPress to 4.3.jklos3-12/+30
2015-08-16Update to 4.2.4 to address security issues:jklos2-6/+6
https://wordpress.org/news/2015/08/wordpress-4-2-4-security-and-maintenance-release/
2015-08-02Security update to version 4.2.3.morr2-6/+6
Changes: WordPress 4.2.3 fixes a cross-site scripting vulnerability, which could allow users with the Contributor or Author role to compromise a site. The release also fixes an issue where it was possible for a user with Subscriber permissions to create a draft through Quick Draft. In addition to the security fixes, WordPress 4.2.3 contains fixes for 21 bugs from 4.2.2, including: * FIX - Upgrades: If a table has already been converted to utf8mb4, there's no need to try and convert it again. * FIX - Remove a redundant index drop. * FIX - Don't upgrade global tables to utf8mb4 when DO_NOT_UPGRADE_GLOBAL_TABLES is defined. * FIX - Enable utf8mb4 for MySQL extension users. * FIX - Plugin update rely upon wp_update_plugins() to check the contents of the transient and return early if no request needs to be made. * FIX - WPDB: When extracting the table name from a query, there is a 1000 character limit on the SQL string that would be searched. * FIX - WPDB: When checking that text isn't too long to insert into a column, LONGTEXT columns could fail, as their length is longer than PHP_INT_MAX. * FIX - Plugin update handles the case where the plugin is installed into a different directory than it previously existed in. * FIX - Plugin update feature doesn't recognize errors * FIX - Plugin update error messages lack detail * FIX - Multiple plugin updates: Even if one of plugins update fails, allow further updates to continue. * FIX - In comment_form(), ensure that filtered arguments contain all required default values. * FIX - WPDB: Remove some of the complexities in ::strip_invalid_text() associated with switching character sets between queries. * FIX - WPDB: ::strip_text_from_query() doesn't pass a length to ::strip_invalid_text(), which was causing queries to fail when they contained characters that needed to be sanity checked by MySQL. * FIX - Emoji script is producing errors on pages with SVG content * FIX - Unable to drag widgets down page past certain length. * FIX - TinyMCE: wpView: fix typo in createInstance that prevented instances from being reused. * FIX - SCRIPT_DEBUG check in print_emoji_detection_script() generated PHP Notices. * FIX - If the shortcode content contains HTML code, the TinyMCE View no longer works. * FIX - Better handling when the credential form is long (such as when SSH is active). * FIX - sanitize_option didn't handle a WP_Error Object.
2015-05-11Security and maintenance update to version 4.2.2.morr3-10/+7
WordPress 4.2.2 fixes a cross-site scripting vulnerability contained in an HTML file shipped with recent Genericons packages included in the Twenty Fifteen theme as well as a number of popular plugins by removing the file. Version 4.2.2 also improves on a fix for a critical cross-site scripting vulnerability introduced in 4.2.1. The release also includes hardening for a potential cross-site scripting vulnerability when using the Visual editor. In addition to the security fixes, WordPress 4.2.2 contains fixes for 13 bugs from 4.2.1, including: o Fixes an emoji loading error in IE9 and IE10 o Fixes a keyboard shortcut for saving from the Visual editor on Mac o Fixes oEmbed for YouTube URLs to always expect https o Fixes how WordPress checks for encoding when sending strings to MySQL o Fixes a bug with allowing queries to reference tables in the dbname.tablename format o Lowers memory usage for a regex checking for UTF-8 encoding o Fixes an issue with trying to change the wrong index in the wp_signups table on utf8mb4 conversion o Improves performance of loop detection in _get_term_children() o Fixes a bug where attachment URLs were incorrectly being forced to use https in some contexts o Fixes a bug where creating a temporary file could end up in an endless loop.
2015-05-04Security update to newest version 4.2.1.morr3-7/+34
Changes: Wordpress 4.2: o Press This has been completely revamped. Clip it, edit it, publish it. Get familiar with the new and improved Press This. From the Tools menu, add Press This to your browser bookmark bar or your mobile device home screen. Once installed you can share your content with lightning speed. Sharing your favorite videos, images, and content has never been this fast or this easy. o Now you can browse and switch installed themes in the Customizer. Browse and preview your installed themes from the Customizer. Make sure the theme looks great with your content, before it debuts on your site. o More intuitive plugin update and install from the Plugins Screen. Goodbye boring loading screen, hello smooth and simple plugin updates. Click Update Now and watch the magic happen. o Writing in WordPress, whatever your language, just got better. WordPress 4.2 supports a host of new characters out-of-the-box, including native Chinese, Japanese, and Korean characters, musical and mathematical symbols, and hieroglyphs. Don’t use any of those characters? You can still have fun — emoji are now available in WordPress! Get creative and decorate your content with 💙, 🐸, 🐒, 🍕, and all the many other emoji. Wordpress 4.2.1: o fix for a critical cross-site scripting (XSS) vulnerability, which could enable commenters to compromise a site.
2015-04-22Security update to version 4.1.2.morr2-6/+6
Changes: 4.1.1: Maintenance release, fixed 21 bugs. 4.1.2: - A serious critical cross-site scripting vulnerability, which could enable anonymous users to compromise a site. - Files with invalid or unsafe names could be uploaded. - Some plugins are vulnerable to an SQL injection attack. - A very limited cross-site scripting vulnerability could be used as part of a social engineering attack. - Four hardening changes, including better validation of post titles within the Dashboard.
2015-01-02Update to version 4.1.morr3-79/+91
Major changes: General - Show the number of approved comments, instead of total comments, in the “At A Glance” section in the dashboard. - Site Language: Install translations on the fly on the General Settings screen. The language drop down now includes installed languages and all available translations when the filesystem is writable by WordPress. - Admin notices: There are now four types of notices: success (green), warning (orange), error (red), and info (blue). Posts - Spellchecking is enabled for the post title field on the Edit Post screen. Media - Disable multi-file uploading in iOS 7.x Safari as it prevents uploading of videos. - Allow PSDs (Photoshop documents) to be uploaded. - oEmbed: Add support for the Vine endpoint. - Display error message when Media Library upload fails. Appearance - Custom Header and Custom Background screens removed. Admin menu links now go to the Customizer. - Widgets screen now has a Manage in Customizer link at top of screen. - Themes: Make "Live Preview" the primary action and “Activate” secondary. Users - Introduce a button on the user profile screen which clears all other sessions, and on the user editing screen which clears all sessions. Accessibility - Admin menu separators are now hidden from screen readers. - Improved keyboard control of Edit Selection mode in the media manager. - Improved keyboard accessibility on Custom Header and Custom Background screen. - Improved text contrast against dark backgrounds in the admin menu and toolbar. - When switching to the Text editor, make the textarea visible to screen readers. - Use <button> instead of <a> for the Visual/Text buttons to make them focusable. - Improve the focus style for review links in the plugin info modal. - TinyMCE: -- Return focus to the editor on pressing Escape while the image toolbar is focused. -- Add a Close button to the Help modal and close it on Escape. -- Override the title on the editor iframe (read by screen reader apps), replace with the Alt+Shift+H shortcut. -- Add focus shortcuts descriptions to the Help modal. Multisite - Set the default network language on the Network Settings screen.
2014-11-24Security update to 4.0.1.morr2-6/+6
Changes: - Three cross-site scripting issues that a contributor or author could use to compromise a site. - A cross-site request forgery that could be used to trick a user into changing their password. - An issue that could lead to a denial of service when passwords are checked. - Additional protections for server-side request forgery attacks when WordPress makes HTTP requests. - An extremely unlikely hash collision could allow a user’s account to be compromised, that also required that they haven’t logged in since 2008 (I wish I were kidding). - WordPress now invalidates the links in a password reset email if the user remembers their password, logs in, and changes their email address. More details on http://codex.wordpress.org/Version_4.0.1.
2014-09-12Update to version 4.0.morr3-14/+32
Major changes: General - Featured image previews now support .bmp files - Featured Image meta box is now hidden for contributors lacking upload capabilities - New supported oEmbed providers: CollegeHumor, Issuu, Mixcloud, YouTube playlists, TED talks - Install WordPress in your language - Streamlined Language management right from the dashboard Posts - Display embed previews for audio/visual URLs in Visual editor content box. - Page scrolling now scrolls post content box. - Edit Post/Page menu bar sticks to top of content box when scrolling (Visual and Text editor). - Color picker was re-added to the Visual editor Media - Add Media Grid view option (default) for Media Library - Add "Bulk Select" button to Media Grid view to delete multiple items - Add oEmbed support for TED talks, Mixcloud, CollegeHumor.com, Issuu - Expand oEmbed support to include YouTube playlist URLs and Polldaddy’s short URL format - Remove Viddler oEmbed support - Update SlideShare oEmbed regex - Improved media experience on small screen sizes (embedded videos now responsive) - Native video and audio shortcodes now support Flash playback looping Comments - Comments in trash can now be marked as spam. Plugins - Display plugins list as grid, with thumbnails, on Add New screen. - Add popup window with plugin details (displays info from plugin's directory page). - Add "Beta Testing" tab to Plugins screen for new features-as-plugins. Accessibility - Improved keyboard accessibility in the Add Media panel - Improved screen-reader support for Customizer sections - Makes links in help tabs keyboard accessible - Improvements for screen-readers when managing widgets in the Customizer Install Process - Add language select menu as first Installation screen (skipped for localized installs) Multisite - mp4 file extension was added to allowed upload file types
2014-08-17Security update to version 3.9.2morr3-7/+8
Changes: * Fixes a possible denial of service issue in PHP’s XML processing, reported by Nir Goldshlager of the Salesforce.com Product Security Team. Fixed by Michael Adams and Andrew Nacin of the WordPress security team and David Rothstein of the Drupal security team. * Fixes a possible but unlikely code execution when processing widgets (WordPress is not affected by default), discovered by Alex Concha of the WordPress security team. * Prevents information disclosure via XML entity attacks in the external GetID3 library, reported by Ivan Novikov of ONSec. * Adds protections against brute attacks against CSRF tokens, reported by David Tomaschik of the Google Security Team. * Contains some additional security hardening, like preventing cross-site scripting that could be triggered only by administrators.
2014-05-16Update to wordpress 3.9.1.morr3-180/+155
Changes: - A smoother media editing experience - Improved visual editing - speed, accessibility, and mobile support - Edit images easily - quicker access to crop and rotation tools, scale images directly in the editor - Drag and drop your images right onto the editor - Image gallery previews right in the editor - Showcase music and clips with simple audio and video playlists - Live widget and header image previews in the Customizer - Stunning new theme browser Version 3.9.1 fixes 34 bugs from 3.9. More details on http://codex.wordpress.org/Version_3.9 and http://codex.wordpress.org/Version_3.9.1
2014-04-13Update to newest version of Wordpress, containing security fixes.morr2-6/+6
It contains 9 bugfixes and 5 security fixes: * Potential authentication cookie forgery. CVE-2014-0166. * Privilege escalation: prevent contributors from publishing posts. CVE-2014-0165. * (Hardening) Pass along additional information when processing pingbacks to help hosts identify potentially abusive requests. * (Hardening) Fix a low-impact SQL injection by trusted users. * (Hardening) Prevent possible cross-domain scripting through Plupload, the third-party library WordPress uses for uploading files.
2014-02-12Update to version 3.8.1morr2-6/+6
Changes: Addressed 31 bugs in 3.8, including various fixes and improvements for the new dashboard design and new themes admin screen. More info at http://codex.wordpress.org/Version_3.8.1
2014-01-23Update to version 3.8.morr3-47/+148
Changes: Introduces a new, modern admin design * A fresh, uncluttered design * Clean typography with Open Sans * Superior contrast and large, comfortable type * Responsive interfaces throughout * Refined, theme management * Smoother, click-to-add widget management New Default Theme - Twenty Fourteen * Easily create a responsive magazine website with a sleek, modern design. * Feature your favorite homepage content in either a grid or a slider. * Use the three widget areas to customize your website, and change your content's layout with a full-width page template and a contributor page to show off your authors. For Developers * External Libraries have been updated. * Better RTL support More info on http://codex.wordpress.org/Version_3.8
2013-11-08Update to 3.7.1 Maintenance Release.morr3-10/+18
Changes: Version 3.7: * Background Updates - Automatic updates for maintenance and security updates. - Daily updates for developers using nightly builds. * Stronger Password Meter - New password meter to encourage users to choose stronger passwords. * Improved Search - More relevant search results. * Better Global Support - Localized versions will receive faster and more complete translations. - Background updates will include translations More info on http://codex.wordpress.org/Version_3.7 Version 3.7.1: - Images with captions no longer appear broken in the visual editor. - Allow some sites running on old or poorly configured servers to continue to check for updates from WordPress.org. - Avoid fatal errors with certain plugins that were incorrectly calling some WordPress functions too early. - Fix hierarchical sorting in get_pages(), exclusions in wp_list_categories(), and in_category() when called with empty values. - Fix a warning that may occur in certain setups while performing a search, and a few other notices. More info on http://codex.wordpress.org/Version_3.7.1
2013-09-12This maintenance release addresses 13 bugs with version 3.6.morr3-11/+7
Additionally: Version 3.6.1 fixes three security issues: * Remote Code Execution: Block unsafe PHP de-serialization that could occur in limited situations and setups, which can lead to remote code execution. Reported by Tom Van Goethem. CVE-2013-4338. * Link Injection / Open Redirect: Fix insufficient input validation that could result in redirecting or leading a user to another website. Reported by Dave Cummo, a Northrup Grumman subcontractor for the U.S. Centers for Disease Control and Prevention. CVE-2013-4339. * Privilege Escalation: Prevent a user with an Author role, using a specially crafted request, from being able to create a post "written by" another user. Reported by Anakorn Kyavatanakij. CVE-2013-4340. Additional security hardening: * Updated security restrictions around file uploads to mitigate the potential for cross-site scripting. The extensions .swf and .exe are no longer allowed by default, and .htm and .html are only allowed if the user has the ability to use unfiltered HTML. More on http://codex.wordpress.org/Version_3.6.1
2013-08-08Update to newest version of Wordpress 3.6.morr3-94/+126
ChangeLog: New Default Theme - Twenty Thirteen * Focus on blogging * Single column layout with Sidebar / Widgets in the footer * Latest Theme Features support, particularly Post Formats and Semantic Markup * Font-based icons (Genericons) Admin Enhancements * UI improvements on Navigation Menus Screen * Revisions revised to be more dynamic and scalable * Autosave and Post Locking * Preview Audio and Video on Media Edit Screen * In-line login following expired sessions For Developers * External Libraries have been updated. * New audio/video APIs give developers access to powerful media metadata, like ID3 tags. * Filters for revisions, allowing you to set the number of revisions ad hoc instead of only via a define. * Semantic Markup allows themes to choose improved HTML5 markup for search forms, comment forms, and comment lists. * Search content for shortcodes with has_shortcode() and adjust shortcode attributes with a new filter. More info on http://codex.wordpress.org/Version_3.6
2013-06-27Fix PLIST file, unbreak buildmorr1-2/+1
2013-06-24Remove pkgrevision bitmorr1-2/+1
2013-06-24Security update to version 3.5.2.morr2-6/+6
Fixed issues: * Server-Side Request Forgery (SSRF) via the HTTP API. CVE-2013-2199. * Privilege Escalation: Contributors can publish posts, and users can reassign authorship. CVE-2013-2200. * Cross-Site Scripting (XSS) in SWFUpload. CVE-2013-2205. * Denial of Service (DoS) via Post Password Cookies. CVE-2013-2173. * Content Spoofing via Flash Applet in TinyMCE Media Plugin. CVE-2013-2204. * Cross-Site Scripting (XSS) when Uploading Media. CVE-2013-2201. * Full Path Disclosure (FPD) during File Upload. CVE-2013-2203. * Cross-Site Scripting (XSS) (Low Severity) when Editing Media. CVE-2013-2201. * Cross-Site Scripting (XSS) (Low Severity) when Installing/Updating Plugins/Themes. CVE-2013-2201. * XML External Entity Injection (XXE) via oEmbed. CVE-2013-2202.
2013-03-16Bump PKGREVISION from default PHP version change to 5.4.obache1-1/+2
2013-01-27This maintenance release addresses 37 bugs with version 3.5, including:morr3-8/+8
* Editor: Prevent certain HTML elements from being unexpectedly removed or modified in rare cases. * Media: Fix a collection of minor workflow and compatibility issues in the new media manager. * Networks: Suggest proper rewrite rules when creating a new network. * Prevent scheduled posts from being stripped of certain HTML, such as video embeds, when they are published. * Work around some misconfigurations that may have caused some JavaScript in the WordPress admin area to fail. * Suppress some warnings that could occur when a plugin misused the database or user APIs. Additionally: Version 3.5.1 fixes a few security issues: * Server-side request forgery (SSRF) and remote port scanning via pingbacks. Fixed by the WordPress security team. * Cross-site scripting (XSS) via shortcodes and post content. Discovered by Jon Cave of the WordPress security team. * Cross-site scripting (XSS) in the external library Plupload. Plupload 1.5.5 was released to address this issue.
2012-12-16Update to version 3.5.morr3-214/+258
Highlights * New Media Manager + Beautiful interface: A streamlined, all-new experience + Create galleries faster with drag-and-drop reordering, inline caption editing, and simplified controls + Insert multiple images at once with Shift/Ctrl+click * New Default Theme - Twenty Twelve + Simple, flexible, elegant + Mobile-first, responsive design + Gorgeous Open Sans typeface + Uses the latest Theme Features * Admin Enhancements + New Welcome Screen + Retina-Ready (HiDPI) Admin + Hide Link Manager for new installs + Better accessibility for screenreaders, touch devices, and keyboard users + More polish on admin screens, including a new color picker * For Developers + WP_Comment_Query and WP_User_Query accept now meta queries just like WP_Query + Meta queries now support querying for objects without a particular meta key + Post objects are now instances of a WP_Post class, which improves performance and caching + Multisite's switch_to_blog() is now significantly faster and more reliable + WordPress has added the Underscore and Backbone JavaScript libraries + TinyMCE, jQuery, jQuery UI, and SimplePie have all been updated to the latest versions + Image Editing API for cropping, scaling, etc., that uses ImageMagick as well as GD + XML-RPC: Now always enabled and supports fetching users, managing post revisions, searching + New "show_admin_column" parameter for register_taxonomy() allows automatic creation of taxonomy columns on associated post-types.
2012-10-28Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days.asau1-3/+1
2012-09-09Update to Wordpress 3.4.2.morr2-6/+6
Changes: * Fixes some issues in the admin area where some older browsers (IE7, in particular) may slow down, lag, or freeze. * Fixes an issue where a theme may not preview correctly, or its screenshot may not be displayed. * Fixes the use of multiple trackback URLs in a post. * Prevents improperly sized images from being uploaded as headers from the customizer. * Ensures proper error messages can be shown to PHP4 installs. (WordPress requires PHP 5.2.4 or later.) * Fixes handling of oEmbed providers that only return XML responses. * Addresses pagination problems with some category permalink structures. * Adds more fields to be returned from the XML-RPC wp.getPost method. * Avoids errors when updating automatically from very old versions of WordPress (pre-3.0). * Fixes problems with the visual editor when working with captions. Additionally: Version 3.4.2 fixes a few security issues and contains some security hardening. These issues were discovered and addressed by the WordPress security team: * Fix unfiltered HTML capabilities in multisite. * Fix possible privilege escalation in the Atom Publishing Protocol endpoint. * Allow operations on network plugins only through the network admin. * Hardening: Simplify error messages when uploads fail. * Hardening: Validate a parameter passed to wp_get_object_terms().
2012-06-29Security update to version of Wordpress 3.4.1.morr3-37/+82
ChangeLog: Wordpress 3.4.1: * Fixes an issue where a theme’s page templates were sometimes not detected. * Addresses problems with some category permalink structures. * Better handling for plugins or themes loading JavaScript incorrectly. * Adds early support for uploading images on iOS 6 devices. * Allows for a technique commonly used by plugins to detect a network-wide activation. * Better compatibility with servers running certain versions of PHP (5.2.4, 5.4) or with uncommon setups (safe mode, open_basedir), which had caused warnings or in some cases prevented emails from being sent. Additionally: Version 3.4.1 fixes a few security issues and contains some security hardening. These issues were discovered and fixed by the WordPress security team: * Privilege Escalation/XSS. Critical. Administrators and editors in multisite were accidentally allowed to use unfiltered_html for 3.4.0. * CSRF. Additional CSRF protection in the customizer. * Information Disclosure: Disclosure of post contents to authors and contributors (such as private or draft posts). * Hardening: Deprecate wp_explain_nonce(), which could reveal unnecessary information. * Hardening: Require a child theme to be activated with its intended parent only. Wordpress 3.4: * Enhanced theme control * Customize theme options before activating a new theme using Theme Customizer * Use Theme Previewer to customize current theme without changing the front-end design * Custom Headers * Improved Custom Headers with flexible sizes * Selecting Custom Header Images and Custom Background Images from Media Library Screen * Media improvements * Support HTML in image captions * Under the Hood improvements * Improvements in WordPress internationalization and localization (more info) * Different split in translation POT files for faster translations * Codex XML-RPC information update accessed via XML-RPC_WordPress_API * WP_Query improvements
2012-04-25Security update to Wordpress 3.3.2.morr2-6/+6
Three external libraries included in WordPress received security updates: * Plupload (version 1.5.4), which WordPress uses for uploading media. * SWFUpload, which WordPress previously used for uploading media, and may still be in use by plugins. * SWFObject, which WordPress previously used to embed Flash content, and may still be in use by plugins and themes. WordPress 3.3.2 also addresses: * Limited privilege escalation where a site administrator could deactivate network-wide plugins when running a WordPress network under particular circumstances. * Cross-site scripting vulnerability when making URLs clickable. * Cross-site scripting vulnerabilities in redirects after posting comments in older browsers, and when filtering URLs.