WordPress 4.9.1 Security Update

·

·

WordPress 4.9.1 was released on November 29 and is a security update. The update fixes four security issues for all versions of WordPress since 3.7. The vulnerabilities could be exploited as part of a multi-vector attack.

The update implements four methods of preventing these kinds of attacks:

  1. Use a properly generated hash for the newbloguser key instead of a determinate substring.
  2. Add escaping to the language attributes used on html elements.
  3. Ensure the attributes of enclosures are correctly escaped in RSS and Atom feeds.
  4. Remove the ability to upload JavaScript files for users who do not have the unfiltered_html capability.

Beside the security fixes also 11 bugs were fixed. One of the fixed bugs was the issues related to the caching of theme files and also the issue with the inability to edit theme and plugin files on Windows based servers was solved.

Remember to create a backup before installing updates.

(Beitragsbild von monsitj)


Kategorien

Beliebte Tags

AI blockchain ecommerce ethics events Magento marketing Metaverse NFTs privacy security SEO shopify socialmedia update WooCommerce WordPress


Der englischsprachige Podcast von Openstream. Discover how memes, AI, and digital culture shape our world, challenge norms, and redefine what it means to be human.

spotify-podcast-badge
Listen on Apple Podcast