WordPress versions 4.9 and earlier are affected by four security issues which could potentially be exploited as part of a multi-vector attack. As part of the core team’s ongoing commitment to security hardening, the following fixes have been implemented in 4.9.1:
- Use a properly generated hash for the
newbloguserkey instead of a determinate substring.
- Add escaping to the language attributes used on
- Ensure the attributes of enclosures are correctly escaped in RSS and Atom feeds.
Thank you to the reporters of these issues for practicing responsible security disclosure: Rahul Pratap Singh and John Blackbourn.
Eleven other bugs were fixed in WordPress 4.9.1. Particularly of note were:
- Issues relating to the caching of theme template files.
- The inability to edit theme and plugin files on Windows based servers.
Download WordPress 4.9.1 or venture over to Dashboard → Updates and click “Update Now.” Sites that support automatic background updates are already beginning to update automatically.