{"id":4676,"date":"2017-01-26T19:34:02","date_gmt":"2017-01-26T19:34:02","guid":{"rendered":"https:\/\/wordpress.org\/news\/?p=4676"},"modified":"2021-06-04T12:00:54","modified_gmt":"2021-06-04T12:00:54","slug":"wordpress-4-7-2-security-release","status":"publish","type":"post","link":"https:\/\/wordpress.org\/news\/2017\/01\/wordpress-4-7-2-security-release\/","title":{"rendered":"WordPress 4.7.2 Security Release"},"content":{"rendered":"

WordPress 4.7.2 is now available. This is a security release<\/strong> for all previous versions and we strongly encourage you to update your sites immediately.<\/p>\n

WordPress versions 4.7.1 and earlier are affected by three\u00a0security issues:<\/p>\n

    \n
  1. The user interface for assigning taxonomy terms in Press This is shown to users who do not have\u00a0permissions to use it. Reported by David Herrera of Alley Interactive<\/a>.<\/li>\n
  2. WP_Query<\/code>\u00a0is vulnerable to a SQL injection (SQLi) when passing unsafe\u00a0data. WordPress core is not directly vulnerable to this issue, but we’ve added hardening to prevent plugins and themes from accidentally causing a vulnerability.\u00a0Reported by\u00a0Mo Jangda<\/a> (batmoo).<\/li>\n
  3. A cross-site scripting (XSS) vulnerability was discovered in the posts list table. Reported by Ian Dunn<\/a>\u00a0of the WordPress Security Team.<\/li>\n
  4. An unauthenticated privilege escalation vulnerability was discovered in a REST API endpoint. Reported by\u00a0Marc-Alexandre Montpas<\/a>\u00a0of Sucuri Security. *<\/li>\n<\/ol>\n

    Thank you to the reporters of these issues for practicing\u00a0responsible disclosure<\/a>.<\/p>\n

    Download WordPress 4.7.2<\/a>\u00a0or venture over to Dashboard \u2192 Updates and simply click \u201cUpdate Now.\u201d Sites that support automatic background updates are already beginning to update to WordPress 4.7.2.<\/p>\n

    Thanks to everyone who contributed to 4.7.2.<\/p>\n

    * Update: An additional serious vulnerability was fixed in this release and public disclosure was delayed. For more information on this vulnerability, additional mitigation steps taken, and an explanation for why disclosure was delayed, please read\u00a0Disclosure of Additional Security Fix in WordPress 4.7.2<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"

    WordPress 4.7.2 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately. WordPress versions 4.7.1 and earlier are affected by three\u00a0security issues: The user interface for assigning taxonomy terms in Press This is shown to users who do not have\u00a0permissions to use it. […]<\/p>\n","protected":false},"author":140668,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"episode_type":"","audio_file":"","cover_image":"","cover_image_id":"","duration":"","filesize":"","date_recorded":"","explicit":"","block":"","filesize_raw":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[14,15],"tags":[189],"class_list":["post-4676","post","type-post","status-publish","format-standard","hentry","category-releases","category-security","tag-4-7"],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pZhYe-1dq","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/posts\/4676","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/users\/140668"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/comments?post=4676"}],"version-history":[{"count":11,"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/posts\/4676\/revisions"}],"predecessor-version":[{"id":4690,"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/posts\/4676\/revisions\/4690"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/media?parent=4676"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/categories?post=4676"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wordpress.org\/news\/wp-json\/wp\/v2\/tags?post=4676"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}