{"id":5645,"date":"2018-04-03T19:56:54","date_gmt":"2018-04-03T19:56:54","guid":{"rendered":"https:\/\/wordpress.org\/news\/?p=5645"},"modified":"2022-11-18T22:53:13","modified_gmt":"2022-11-18T22:53:13","slug":"wordpress-4-9-5-security-and-maintenance-release","status":"publish","type":"post","link":"https:\/\/wordpress.org\/news\/2018\/04\/wordpress-4-9-5-security-and-maintenance-release\/","title":{"rendered":"WordPress 4.9.5 Security and Maintenance Release"},"content":{"rendered":"\n

WordPress 4.9.5 is now available. This is a security and maintenance release<\/strong> for all versions since WordPress 3.7. We strongly encourage you to update your sites immediately.<\/p>\n\n\n\n

WordPress versions 4.9.4 and earlier are affected by three security issues. As part of the core team's ongoing commitment to security hardening, the following fixes have been implemented in 4.9.5:<\/p>\n\n\n\n

    \n
  1. Don't treat localhost<\/code> as same host by default.<\/li>\n
  2. Use safe redirects when redirecting the login page if SSL is forced.<\/li>\n
  3. Make sure the version string is correctly escaped for use in generator tags.<\/li>\n<\/ol>\n\n\n\n

    Thank you to the reporters of these issues for practicing \ufeffcoordinated security disclosure<\/a>:\u00a0xknown<\/a> of the WordPress Security Team,\u00a0Nitin Venkatesh (nitstorm)<\/a>, and Garth Mortensen<\/a> of the WordPress Security Team.<\/p>\n\n\n\n

    Twenty-five other bugs were fixed in WordPress 4.9.5. Particularly of note were:<\/p>\n\n\n\n