WordPress 5.2.3 Security and Fix-Update

·

·

After a summer break from updates, WordPress 5.2.3 received new security and bug fixes on September 5. For older versions of WordPress (down to 3.8.x) there is also a fix for jQuery, which was already in version 5.2.1, but not available for older versions of WordPress. WordPress 5.2.3 also fixes over 20 design and functionality issues in certain configurations.

Fixed Vulnerabilities

  • Cross-site scripting vulnerability in post previews by contributors.
  • Cross-site scripting vulnerability in stored comments.
  • Validation and sanitization of a URL could lead to an open redirect.
  • Cross-site scripting during media uploads.
  • Cross-site scripting in shortcode previews.
  • Reflected cross-site scripting in the dashboard.
  • URL sanitization that can lead to cross-site scripting (XSS) attacks.

Bug Fixes

  • New Custom Link menu item has a wrong fallback label
  • Block Editor: $editor_styles bug
  • A URL in do_block_editor_incompatible_meta_box function does not have classic-editor__forget parameter
  • Media Trash: The Bulk Media options when in the Trash shouldn’t provide two primary buttons
  • Media Trash: Primary button(s) should be on the left
  • Ensure that tables generated by the Settings API have no semantics
  • Incorrect version for excerpt_allowed_blocks filter
  • Media views: dismiss notice button is invisible
  • Feature Image dialog does not follow the dialog pattern
  • Twenty Seventeen: Native audio and video embeds have no focus state
  • Twenty Nineteen: Revise Latest Posts block styles to support post content options
  • Fix headings hierarchy in the legacy Custom Background and Custom Header pages
  • Improve accessibility of forms elements within some “form-table” forms
  • Twenty Seventeen: Button block preview has extra spacing within button
  • Fix tab sequence order in the Media attachment browser
  • Emoji are substituted in preformatted blocks
  • Media modal bottom toolbar cuts-off content in Internet Explorer 11
  • Minor Verbiage Update – Switch ‘developer time’ for ‘a developer’
  • Twenty Seventeen: buttons don’t change color on hover and focus
  • Plugin: View details popup layout issue
  • My account toggle on admin bar not visible at high zoom levels
  • Undefined variable: locked in wp-admin/edit-form-blocks.php
  • Use alt tags for gallery images in editor
  • Color hex code in color picker displayed in RTL instead of LTR on RTL install
  • Customizer Color picker should get closed when click on color picker area.
  • Adding a custom link in nav-menus.php doesn’t trim whitespace
  • Font sizes on installation screen are too small
  • PHP requirement always set to null for plugins
  • Adding a custom link in menu via Customize doesn’t trim whitespace.

Remember to create a backup before updating your site.