WordPress 5.4.1 Fixes 17 Security Bugs Update Now

Wordpress Security
Wordpress Security

Are your Website running on WordPress? Update Now!

WordPress Fixes 17 security Bugs, including 7 are critical and released a new WordPress 5.4.1 Version.

The vulnerabilities include Cross Site Scripting and an authenticated XSS issue in the block editor was discovered in WordPress 5.4 RC1 and RC2. It has fixed in 5.4 RC5.

WordPress said in its blog, 5.4.1 is a short-cycle security and maintenance release. The next major release will be version 5.5. All versions since WordPress 3.7 have also been updated.

Security updates

Six security issues affect WordPress versions 5.4 and earlier; version 5.4.1 fixes them, so you’ll want to upgrade. If you haven’t yet updated to 5.4, there are also updated versions of 5.3 and earlier that fix the security issues.

Following vulnerabilities have been fixed in WordPress 5.4.1

  • An issue in Password reset tokens were not correctly invalidated.
  • Private posts could be viewed without authentication.
  • Two cross-site scripting (XSS) vulnerabilities in the customizer.
  • XSS issue in the search block.
  • XSS issue in the WordPress wp-object-cache.
  • XSS issue with file uploads.
  • An authenticated XSS issue in the block editor in WordPress 5.4 Release Candidates RC1 and RC2 (fixed in 5.4 RC5).

Maintenance updates

WordPress 5.4.1 also fixes some regressions introduced in version 5.4:

  • Accessibility: Fix the headings hierarchy on the Freedoms page
  • Customize: Give the WordPress logo a white background for dark mode browsers
  • Mail: Make the check for empty post title in wp-mail.php more resilient
  • Media: Remove display: none; from the (visually hidden) <input type=”file”> button used in Plupload to select files for uploading. Fixes selecting files in Edge <= 44 and iOS Safari
  • Privacy: Support additional elements (table, ol, ul) in privacy policy guide new styling
  • Privacy: Make the deprecated wp_get_user_request_data() function available on front end
  • REST API: Fix revisions controller get_item permission check
  • REST API: Fix _fields filtering of registered rest fields
  • Site Health: Instantiation prevents use of some hooks by plugins
  • Taxonomy: Un-deprecate category_link and tag_link filters
  • Block Editor updates

Updated packages

To download WordPress 5.4.1, update automatically from the Dashboard > Updates menu in your site’s admin area or visit https://wordpress.org/download/release-archive/.

You can download WordPress 5.4.1 by downloading from WordPress.org, or visit your Dashboard → Updates and click Update Now.

For the latest update about Cyber and Infosec World, follow us on Twitter, Facebook, Telegram , Instagram and subscribe to our YouTube Channel.

Subscribe to HackersOnlineClub via Email

Enter your Email address to receive notifications of Latest Posts by Email | Join over Million Followers

Tags from the story
More from Priyanshu Sahay

GDA- Android Reverse Engineering Suite

GDA (GJoy Dex Analyzer) – Android Reverse Engineering Suite Android Malware Static...
Read More

Leave a Reply