Trusted WordPress tutorials, when you need them most.
Beginner’s Guide to WordPress
Coupe WPB
25 Million+
Websites using our plugins
16+
Years of WordPress experience
3000+
WordPress tutorials
by experts

WordPress 3.5.2 – Version de maintenance et de sécurité

C’est vendredi et la journée de travail est presque terminée ici sur la côte Est des États-Unis, mais nous sommes toujours en train de mettre à jour tous nos sites WordPress au moment où nous écrivons ces lignes. L’équipe de WordPress a publié WordPress 3.5.2, une mise à jour de maintenance et de sécurité. Dans cette version, l’équipe de sécurité de WordPress a résolu sept problèmes de sécurité et a ajouté des mesures de renforcement de la sécurité. Nous vous recommandons vivement de mettre à niveau vos sites WordPress dès maintenant.

Les corrections de sécurité de WordPress 3.5.2 incluent :

  • Bloquer les attaques de falsification de demande côté serveur, qui pourraient potentiellement permettre à un attaquant d’accéder à un site.
  • Empêcher les contributeurs/contributrices de publier indûment des publications ou de réattribuer la paternité de l’article.
  • Une mise à jour de la bibliothèque externe SWFUpload pour corriger des vulnérabilités de type cross-site scripting.
  • Prévention d’une attaque par déni de service, affectant les sites utilisant des publications protégées par mot de passe.
  • Mise à jour d’une bibliothèque externe TinyMCE pour corriger une vulnérabilité de script intersite.
  • Plusieurs corrections pour les scripts intersites.
  • Éviter de divulguer le chemin complet d’un fichier lorsqu’un téléversement échoue.

Passer à la version 3.5.2 de WordPress. Allez dans votre Tableau de bord  » Mises à jour et faites-le en 1 clic.

Divulgation : Notre contenu est soutenu par les lecteurs. Cela signifie que si vous cliquez sur certains de nos liens, nous pouvons gagner une commission. Consultez comment WPBeginner est financé, pourquoi cela compte et comment vous pouvez nous soutenir. Voici notre processus éditorial.

Avatar

Editorial Staff at WPBeginner is a team of WordPress experts led by Syed Balkhi with over 16 years of experience in WordPress, Web Hosting, eCommerce, SEO, and Marketing. Started in 2009, WPBeginner is now the largest free WordPress resource site in the industry and is often referred to as the Wikipedia for WordPress.

L'ultime WordPress Toolkit

Accédez GRATUITEMENT à notre boîte à outils - une collection de produits et de ressources liés à WordPress que tous les professionnels devraient avoir !

Reader Interactions

21 commentairesLaisser une réponse

  1. Syed Balkhi

    Hey WPBeginner readers,
    Did you know you can win exciting prizes by commenting on WPBeginner?
    Every month, our top blog commenters will win HUGE rewards, including premium WordPress plugin licenses and cash prizes.
    You can get more details about the contest from here.
    Start sharing your thoughts below to stand a chance to win!

  2. Adnan Fasih

    There are so many issues in 3.5.2 update. Admin panel is disappearing; I had to manually fix the wp-admin folder from FTP. This is disappointing first 3.5.2 contains multiple issues and now 3.6 is further delayed. :(

  3. Gautam Thapar

    There seems to be some changes related to date format as well. First of all I noticed it in google webmaster tools which displayed error related to sitemap date. I use sitemap generated through Wordpress SEO by Yoast.

    Then I noticed it in my custom post type backend where the list of posts use to display in this format – ‘2013/06/17 Published’ but now after the update it is displaying in the format which I use for the frontend – ‘1 hour ago Published’. :(

  4. Len Printz

    Hi guys! We updated to 3.5.2 and now our media library isn’t functioning properly…when trying to post an image to a page, we don’t see any of our images in the library and, also, our Nivo slider just chugs and we can’t manage that either!

    Any ideas would be MOST appreciated!

    Thanks so much!

  5. Stark

    Good to know, thanks so much.

  6. Claire

    Upgrade appears to have worked beautifully! Thanks much.

  7. Joseph

    Fine for me! Everything worked just fine. I have two sites with different themes and both had no issues with the update.

  8. Terence

    I am always grateful for all the work the guys do behind the scenes keeping my site safe. But this really was the worst experience I have had with an update in all the years I have worked with WordPress, and from what I can see in the WordPress forums I am not the only one.

    In the end I had to disconnect my CDN and remove all my security and deactivate every plugin, only then would it install.

    Be very VERY careful with 3.5.2 and as you should do anyway, be sure to take a complete backup (website and SQL), before trying to install this update.

    Terence.

    • Editorial Staff

      That is rather strange Terence. Our WordPress 3.5.2 update worked just fine. We did have an issue where caching stopped, but that was due to an update of another plugin « WordPress SEO by Yoast », but he was very quick to roll out another update with fixes.

      Administrateur

      • Terence

        Which just goes to show how no two sites are alike, except superficially.

        The one problem I didn’t have a problem with ~ at least nothing to do with 3.5.2 ~ was Joost’s.

      • Terence

        Ooops! I take that back… WP SEO is now showing a red banner and claiming I have to remove `<meta name="description" content=" » />` from my theme, and it then offers to fix it for me automagically, but although it offers, it doesn’t work.

        • Editorial Staff

          Well you shouldn’t have meta description tag in your theme if you are using WordPress SEO by Yoast.

  9. Mary

    Thank you for this awesome rundown.

    I do tend to « shake in the knees » whenever I update anything. Of course, I do it antway!!!
    I have lost headers and footers. I hope it doesnt happen with a WP update.

    Nonetheless, the Wordpress team is truly amazing.

    I really like your site alot. You cover so many important topics and you do it well!

    Thank you! Mary

  10. kurtis

    being new to wordpress and your site…. is there proper things I should before I update? I read BACKUP, deactivate all plugins and then update. Is the the correct thing to do? can you please steer me in the right direction… I am in the middle of building a huge ecommerce site with woocommerce and I don’t want to loose or affect anything I am currently working on. I have woodojo launchpad enable during this build

    thank you! I love your blog!

    would love to see more info on e commerce like SEO, builds etc just an idea for you ;)

    • Editorial Staff

      Having a regular backup is necessary. We use a paid service VaultPress by Automattic to handle our real-time backup. We simply click on the one-click update and it works.

      Administrateur

  11. Keith Davis

    Thanks guys
    All sites now updated and looking good.
    Love the WordPress one-click update.

  12. iAn

    I am done updating with my membership sites but there is this strange activity happening – I keep on receiving spam registrations…i am using si captcha for security…i have disabled the registrations for the moment.

  13. Anmol Makkar

    Does it changes, any edits I’ve made to themes and plugins in PHP editor?

Laisser une réponse

Merci d'avoir choisi de laisser un commentaire. Veuillez garder à l'esprit que tous les commentaires sont modérés selon notre politique de commentaires, et votre adresse e-mail ne sera PAS publiée. Veuillez NE PAS utiliser de mots-clés dans le champ du nom. Ayons une conversation personnelle et significative.