Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,194,821 members, 7,956,091 topics. Date: Monday, 23 September 2024 at 01:32 AM

Wordpress Security Update 4.8.2 – Update Immediately - Webmasters - Nairaland

Nairaland Forum / Science/Technology / Webmasters / Wordpress Security Update 4.8.2 – Update Immediately (363 Views)

Wordpress Security Plugins Compared To Find Which Works Best / Wordpress Security: The Complete Guide / 4 Best Wordpress Security Plugins For Wordpress Users In 2017 (2) (3) (4)

(1) (Reply)

Wordpress Security Update 4.8.2 – Update Immediately by solaugo1: 6:33am On Sep 20, 2017


WordPress Core version 4.8.2 has just been released. This is a minor update and a security release which means that your sites will update automatically within the next 24 hours unless you have disabled auto updates.

The update includes a fix to $wpdb->prepare() to help protect against SQLi injection attacks. WordPress core is not vulnerable to SQLi injection attacks directly, but certain plugins and themes may be vulnerable depending on how they use the $wpdb->prepare() function in their code. This fix alone is reason to update immediately to 4.8.2.

The release fixes five cross site scripting vulnerabilities. These are in:

oEmbed discovery
The visual editor
The plugin editor
In template names

Two path traversal vulnerabilities were fixed. These are:

In the file unzipping code
In the customizer

An open redirect was also fixed on the user and term editing screens. 4.8.2 also includes 6 maintenance fixes.

Now that the existence of these vulnerabilities is public, it becomes much more likely that they will be exploited. It is very important that you update as soon as possible to 4.8.2.

To update manually now you can sign into your WordPress site, mouse over the Dashboard on the top left and click ‘Updates’ and complete the update process.

Please share this information with the rest of the community to ensure everyone updates in a timely fashion. Thanks.

Resources:

You can find the full announcement here.
The release notes are here.
The list of changes are on this page.
You can download WordPress 4.8.2 on this page.

Are you having challenges with your Wordpress Installations? Get in touch with ASSURE Educational Services - 07063397940, 08050701465, admin@assure.ng for a quick fix.

Did you enjoy this post? Share it!

https://news.assure.ng/wordpress-security-update-4-8-2-update-immediately/
Re: Wordpress Security Update 4.8.2 – Update Immediately by SConnect: 6:52am On Sep 20, 2017
Good.

Re: Wordpress Security Update 4.8.2 – Update Immediately by Finstar: 7:10am On Sep 20, 2017
Nice development

(1) (Reply)

Cheap Wordpress Training And Certification / Get Autoresponder, Web Hosting, Lead Capture Pages And Many More Just $10/month / Help Review Afia9 Online Shop

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 8
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.