Support Forum

Advanced Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
news-topic
Critical Security Update - Version 5.5.0.1 Released
Avatar
Mr Papa
Simi Valley, CA
SP Master
Free Members
sp_UserOfflineSmall Offline
Aug 12, 2014 - 8:50 pm
sp_QuotePost Quote

security-updateImage EnlargerToday, we have released an urgent security update to Simple:Press. We strongly encourage you to update your sites running Simple:Press immediately.

This release corrects a potential sql injection vulnerability in the search function of Simple:Press. The bug was reported by a Simple Press user that wishes to remain anonymous. We want to thank him for the responsible reporting of this issue so it could be researched and resolved.

So please be sure to update your installations of Simple:Press...

The next planned version of Simple:Press, v5.5.1, is still on target for release in a couple weeks when the WordPress team ships their 4.0 version.

Avatar
Blaise
Member
Pro Subscribers
sp_UserOfflineSmall Offline
Aug 14, 2014 - 4:32 am
sp_QuotePost Quote

Hi,

Could you please let me know which files were updated so I can just replace those files? I have done quite a few customisations and do not want to overwrite them all.

thanks!

Avatar
Yellow Swordfish
Glinton, England
SP Master
sp_UserOfflineSmall Offline
Aug 14, 2014 - 5:02 am
sp_QuotePost Quote

/sp-control.php
/sp-api/sp-api-primitives.php
/forum/content/classes/sp-search-view-class.php

I have to say that making changes to core code is a really, really bad idea. It should also be unnecessary. Like WordPress itself, Simple:Press has an extremely rich set of WP style hooks - actions and filters - which should result in there being no need to customise any code at all. Plus most of the time - customisation can be performed in templates with the creation of a child theme.

When users have asked for a specific customisation they need and there has been no hook available we have always put one in place for them to use and will continue to do so in the future.

andy-signature.png
YELLOW
SWORDFISH
Forum Timezone: Europe/Stockholm
Most Users Ever Online: 1170
Currently Online:
Guest(s) 1
Currently Browsing this Page:
1 Guest(s)
Top Posters:
Mr Papa: 19448
Ike: 2086
Brandon: 864
kvr28: 804
jim: 650
FidoSysop: 577
Conrad_Farlow: 531
fiddlerman: 358
Stefano Prete: 325
Member Stats:
Guest Posters: 620
Members: 17365
Moderators: 0
Admins: 4
Forum Stats:
Groups: 7
Forums: 17
Topics: 10128
Posts: 79626