Automattic has just released the new WordPress 4.7.2, another updated version of the popular CMS. The new version comes with some security improvements. According to the official announcement:
“Versions prior to WordPress 4.7.1 and 4.7.1 are affected by three security issues:
The user interface in the taxonomy terms of Press This is displayed to users who do not have permission to use it. Reported by David Herrera of Alley Interactive.
WP_Query is vulnerable to SQL injection (SQLi). WordPress core is not directly vulnerable to this issue, but we have hardened it further to prevent issues from plugins. Reported by Mo Jangda (batmoo).
A cross-site scripting (XSS) vulnerability was discovered in the message list panel. Reported by Ian Dunn of the WordPress security team.”
Read more
https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
Download the new version or upgrade directly from the admin panel.
