Recalbox 4.1 release date11/14/2022 In addition to the security researchers mentioned above, thank you to everyone who helped make WordPress 5.4.1 happen:Īlex Concha, Andrea Fercia, Andrew Duthie, Andrew Ozz, Andy Fragen, Andy Peatling, arnaudbroes, Chris Van Patten, Daniel Richards, DhrRob, Dono12, dudo, Ehtisham Siddiqui, Ella van Durpe, Garrett Hyder, Ian Belanger, Ipstenu (Mika Epstein), Jake Spurlock, Jb Audras, John Blackbourn, John James Jacoby, Jonathan Desrosiers, Jorge Costa, K. This gave the security team time to fix the vulnerabilities before WordPress sites could be attacked.įor more information, browse the full list of changes on Trac, or check out the version 5.4.1 HelpHub documentation page. Thank you to all of the reporters for privately disclosing the vulnerabilities. We wanted to be sure to give credit and thank them for all of their work in making WordPress more secure. Additionally, an authenticated XSS issue in the block editor was discovered by Nguyen The Duc ( ducnt) in WordPress 5.4 RC1 and RC2.Props to Weston Ruter for fixing a stored XSS vulnerability in the WordPress customizer.Props to Ronnie Goodrich ( Kahoots) and Jason Medeiros who independently reported an XSS issue in file uploads.Props to Nick Daugherty from WordPress VIP / WordPress Security Team who discovered an XSS issue in wp-object-cache.Props to Ben Bidner from the WordPress Security Team who discovered an XSS issue in the search block.Props to Evan Ricafort for discovering an XSS issue in the Customizer.Props to ka1n4t for finding an issue where certain private posts can be viewed unauthenticated.Props to Muaz Bin Abdus Sattar and Jannes who both independently reported an issue where password reset tokens were not properly invalidated.If you haven’t yet updated to 5.4, all WordPress versions since 3.7 have also been updated to fix the following security issues: Seven security issues affect WordPress versions 5.4 and earlier. If you have sites that support automatic background updates, they’ve already started the update process. You can download WordPress 5.4.1 by downloading from, or visit your Dashboard → Updates and click Update Now. The next major release will be version 5.5. WordPress 5.4.1 is a short-cycle security and maintenance release. All versions since WordPress 3.7 have also been updated. Because this is a security release, it is recommended that you update your sites immediately. This security and maintenance release features 17 bug fixes in addition to 7 security fixes.
0 Comments
Leave a Reply.AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |