WordPress 4.7.5 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately.
WordPress versions 4.7.4 and earlier are affected by six security issues:
- Insufficient redirect validation in the HTTP class. Reported by Ronni Skansing.
- Improper handling of post meta data values in the XML-RPC API. Reported by Sam Thomas.
- Lack of capability checks for post meta data in the XML-RPC API. Reported by Ben Bidner of the WordPress Security Team.
- A Cross Site Request Forgery (CRSF) vulnerability was discovered in the filesystem credentials dialog. Reported by Yorick Koster.
- A cross-site scripting (XSS) vulnerability …Read More
Source:: WordPress 4.7.5 Security and Maintenance Release
The following two tabs change content below.Michael Cropper
Founder & Managing Director at Contrado Digital LtdMichael founded Contrado Digital in 2013. He has experience working with national and multi-national brands in a wide range of industries, helping them achieve awesome results. Michael regularly speaks at local universities and industry events while keeping up with the latest trends in the digital industry.Latest posts by Michael Cropper (see all)
- How to Setup Selenium Using Java and Apache NetBeans for Automated Web Browser Testing - February 25, 2021
- How to Host a Single Website Behind a pfSense Firewall - February 19, 2021
- How to Setup Let’s Encrypt on pfSense - February 15, 2021