I love Charleston SC and I love WordPress. It has been a great day .

I love Charleston SC and I love WordPress. It has been a great day .
From the announcement post, this maintenance release addresses 13 bugs with version 3.6.
Additionally: Version 3.6.1 fixes three security issues:
- Remote Code Execution: Block unsafe PHP de-serialization that could occur in limited situations and setups, which can lead to remote code execution. Reported by Tom Van Goethem. CVE pending.
- Privilege Escalation: Prevent a user with an Author role, using a specially crafted request, from being able to create a post “written by” another user. Reported by Anakorn Kyavatanakij. CVE pending.
- Link Injection / Open Redirect: Fix insufficient input validation that could result in redirecting or leading a user to another website. Reported by Dave Cummo, a Northrup Grumman subcontractor for the U.S. Centers for Disease Control and Prevention. CVE pending.
Additional security hardening:
- Updated security restrictions around file uploads to mitigate the potential for cross-site scripting. The extensions .swf and .exe are no longer allowed by default, and .htm and .html are only allowed if the user has the ability to use unfiltered HTML.
A full log of the changes made for 3.6.1 can be found at http://core.trac.wordpress.org/log/branches/3.6?stop_rev=24972&rev=25345.
The WordPress maintenance service bundles premium WordPress services into one affordable WordPress Maintenance Package.
Consultation time, web development, hosting migration and content changes would be a separate service, quoted & billed for as needed.
*dependant on the level of support.
Hi Andrew,
Wow! I was impressed with the quality that you provided for such remarkable turn-around time, and the miniscule amount of time you needed to complete this project. In my failed attempt to produce my primitive version of this website, I read over 100 pages of instructions, completed tutorials on the internet, viewed “how-to-do-it” videos, skimmed two books, “published” (uploaded) each webpage countless times, and spent well over 40 hours failing to produce what you accomplished in minutes. Good for you (and of course, good for me to have found you)!Steven Heller
Steven had called up the office because he was having a hard time building his website using Adobe Contribute. Greenville Web had an old article on building websites using Adobe Contribute and that’s how Steven found us.
After a quick consultation I could see that Contribute was not the right solution and about an hour after I had received the copy and images for Steven’s website I had him set up at WordPress.com with free hosting and a great looking website.
I don’t normally pat myself on the back but after reading what Steven wrote (above) I felt that I wanted to share it.
WordPress, as a Content Management System, is a secure platform. The Weak link is YOU!
Yup it’s your password the one that you use for every website from bank accounts to email. It could be your dog’s name, wife’s middle name and birthday, it’s something that no-one who didn’t know you would ever guess.
WPScan is a “WordPress Security Scanner” Sponsored by the RandomStorm Open Source Initiative *. WPScan like a scalpel is a great tool in the right hands, it’s just destructive when used by the malicious or the criminal.
WPScan is free and available to anyone with an internet connection.
Using WPScan a bad player can attack your login using the aptly named Brute Force Attack **.
A Brute Force Attack is when software like WPScan is used to figure out your website’s username, easy if it is admin, once it has that it will try every possible password until it succeeds.
If your password is letmein or jesus ***, God help you! You’ll be owned in a few hours.
WordPress.org has finalized WordPress 3.4 and is planning on pushing out the update early next week.
I have tested and confirmed that both the Easy Sign Up plugin (and extras) and the Easy Heads Up Bar are working great in WordPress 3.4 Release Candidate 2.
So that is one less thing for my users to worry about.
I do suggest that you back up your website’s theme, uploads, plugin files and your database before any major update.
If you need help with this we offer a WordPress no Stress back up and upgrade service, just contact me with your details and we’ll get you upgraded the right way!
If you find the WordPress welcome panel a tad irritating or a distraction to your WordPress clients pop this code in your themes functions file – or better yet make a plugin and put the code in that.
The welcome panel will still be accessible under the screen options panel but it will be turned off by default.
add_action('wp_dashboard_setup', 'hide_wp_welcome_panel' );
function hide_wp_welcome_panel()
{
if ( current_user_can( 'edit_theme_options' ) )
$ah_clean_up_option = update_user_meta( get_current_user_id(), 'show_welcome_panel', false );
}
This is the official, very quick, video introducing WordPress 3.3.
WordPress 3.3 is available and trust me it’s incredibly cool.
But don’t be tempted to update before you back up your current installation.
The not so quick and easy method is to:
BundleHunt Mega Holiday Bundle, has a retail value of over $1100 for Just $49.99! Read more