4.1.2 security release detail
-
Hi all!
The 4.1.2 official announcement is light on detail about the “critical cross-site scripting vulnerability, which could enable anonymous users to compromise a site.”
The code changes are surely helpful, though I’m not sure which is the critical patch.
The broad add_query_arg() XSS announcement from a day earlier may be related?
Is someone able to provide pointers to more detail, conversation, or risk assessment? Specifically, do any of the recommended WordPress hardening strategies mitigate the risk, such as limiting access to wp-admin paths?
Thank you for any additional detail.
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
- The topic ‘4.1.2 security release detail’ is closed to new replies.