WordPress releases version 4.7.5 fixing six security and three general issues
WordPress has released an updated version 4.7.5 that mostly contains a security and maintenance release for the content management system, which fixes six major issues that were affected in earlier versions.
The security flaws covered in this release is as follows.
- The insufficient redirect validation in the HTTP class.
- Improper handling of post Meta data values in the XML-RPC API.
- Lack of capability checks for post Meta data in the XML-RPC API.
- Cross Site Request Forgery (CRSF) vulnerability was discovered in the file system credentials dialog.
- A cross-site scripting (XSS) vulnerability was discovered when attempting to upload very large files.
- A cross-site scripting (XSS) vulnerability was discovered related to the Customizer.
The XSS bug has been creating vulnerability in millions of WordPress websites. Along with these six security issues, there were also three general maintenance issues fixed in the latest version.
Comments ( 0 )
No comments available