WordPress har uppdaterats till version 4.7.2 och det är en viktig säkerhetsuppdatering som åtgärdar flera rapporterade säkerhetsproblem.
De nu korrigerade buggarna är allvarliga och du uppmanas att uppdatera din WordPress-sajt, omgående. Se också till att alltid ha automatiska uppdateringar påslagna för alla viktiga säkerhetsuppdateringar.
WordPress 4.7.2 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately.
WordPress versions 4.7.1 and earlier are affected by three security issues:
The user interface for assigning taxonomy terms in Press This is shown to users who do not have permissions to use it. Reported by David Herrera of Alley Interactive.
WP_Query is vulnerable to a SQL injection (SQLi) when passing unsafe data. WordPress core is not directly vulnerable to this issue, but weve added hardening to prevent plugins and themes from accidentally causing a vulnerability. Reported by Mo Jangda (batmoo).
A cross-site scripting (XSS) vulnerability was discovered in the posts list table. Reported by Ian Dunn of the WordPress Security Team.
0 kommentarer