HomeSecurityWordPress 4.7.1 with 8 security updates and 61 fixes

WordPress 4.7.1 with 8 security updates and 61 fixes

Version 4.7.1 of the WordPress CMS has just been released with 8 security updates and fixes for 61 bugs from the previous version.

Below are the security vulnerabilities fixed in the new WordPress update:WordPress

Remote Code Execution (RCE) in PHPMailer
REST API exposed data for all users who had written a post. WordPress 4.7.1 limits this to post types that we specify should be displayed.
Cross-site scripting (XSS) via plugin name or update-core.php version header.
Cross-site request forgery (CSRF) bypass via a Flash file.
Cross-site scripting (XSS) via theme name fallback.
Checking whether the default mail.example.com setting has been changed to allow posts from email.
A Cross-site request forgery (CSRF) discovered in widget editing.
Low encryption security in multisite activation key.

You can read the bug fixes from the link below.

https://codex.wordpress.org/Version_4.7.1

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS