February 8, 2012

Check your install for unfiltered_html

Just before the last release, the check for unfiltered_html snuck back into the code base for MU. This means that if you’re using code since then, your users can insert malicious code into your site.

Please read this forum post from Donncha for more details. You can update the wp-admin/includes/schema.php so new blogs won’t have this, and Donncha has provided a plugin to strip it off any blogs that may be using it.

It is very important that you check your codebase for this.

Get 3 for the price of 2 in the Network Home Bundle

Includes 3 ebooks with plugins -
Network Home Pages: aggregate global content, set up sitewide tags, create a huge tags cloud like the one seen on WordPress.com, global footers and menus, setting defaults & more
Custom Registration: sign up on sub sites, multilingual signup pages, stop spam blogs
WP Curator: pick and choose posts from sub sites to feature on the main home page of your network

Network Home Pages, Custom Registration & WP Curator – $35.90 for all three. Purchase

Comments

  1. Andrea says:

    Il s’agit juste d’un test.

    Esto es sólo una prueba.

  2. Arabica says:

    Hi Andrea,

    Sirry to pump this old post.
    Just want to mention a broken link to Donncha’s post.