Wordpress 2.0.6 has been released. It includes some security fixes and minor bugfixes detailed here.

Here’s what’s new:

  • The aforementioned security fixes.
  • HTML quicktags now work in Safari browsers.
  • Comments are filtered to prevent them from messing up your blog layout.
  • Compatibility with PHP/FastCGI setups.

For developers, there’s a new anti-XSS function called attribute_escape(), and a new filter called “query” which allows you filter any SQL at runtime. (Which is pretty powerful.) Thanks to Mark Jaquith for handling this release and Stefan Esser for responsibly reporting the security issue.

The Wordpress team states that this is the last update until version 2.1 is released.

drzy.com has been updated to this version. Please send me a message if anything acts up.