{"id":5376,"date":"2018-01-16T23:00:14","date_gmt":"2018-01-16T23:00:14","guid":{"rendered":"https:\/\/wordpress.org\/news\/?p=5376"},"modified":"2022-11-18T22:53:13","modified_gmt":"2022-11-18T22:53:13","slug":"wordpress-4-9-2-security-and-maintenance-release","status":"publish","type":"post","link":"https:\/\/wordpress.org\/news\/2018\/01\/wordpress-4-9-2-security-and-maintenance-release\/","title":{"rendered":"WordPress 4.9.2 Security and Maintenance Release"},"content":{"rendered":"\n

WordPress 4.9.2 is now available. This is a security and maintenance release<\/strong> for all versions since WordPress 3.7\ufeff. We strongly encourage you to update your sites immediately.<\/p>\n\n\n\n

An XSS vulnerability was discovered in the Flash fallback files in MediaElement, a library that is included with WordPress. Because the Flash files are no longer needed for most use cases, they have been removed from WordPress.<\/p>\n\n\n\n

MediaElement has released a new version that contains a fix for the bug, and a WordPress plugin containing the fixed files<\/a> is available in the plugin repository.<\/p>\n\n\n\n

Thank you to the reporters of this issue for practicing responsible security disclosure<\/a>:\u00a0Enguerran Gillier<\/a>\u00a0and\u00a0Widiz\ufeff<\/a>.<\/p>\n\n\n\n

21 other bugs were fixed in WordPress 4.9.2. Particularly of note were:<\/p>\n\n\n\n