WordPress 5.5.2 is now available!
This security and maintenance release features 14 bug fixes in addition to 10 security fixes. Because this is a security release , it is recommended that you update your sites immediately. All versions since WordPress 3.7 have also been updated.
WordPress 5.5.2 is a short-cycle security and maintenance release. The next major release will be version 5.6.
You can download WordPress 5.5.2 by downloading from WordPress.org, or visit your Dashboard → Updates and click Update Now.
If you have sites that support automatic background updates, they've already started the update process.
Ten security issues affect WordPress versions 5.5.1 and earlier. If you haven't yet updated to 5.5, all WordPress versions since 3.7 have also been updated to fix the following security issues:
- Props to Alex Concha of the WordPress Security Team for their work in hardening deserialization requests.
- Props to David Binovec on a fix to disable spam embeds from disabled sites on a multisite network.
- Thanks to Marc Montas from Sucuri for reporting an issue that could lead to XSS from global variables.
- Thanks to Justin Tran who reported an issue surrounding privilege escalation in XML-RPC. He also found and disclosed an issue around privilege escalation around post commenting via XML-RPC.
- Props to Omar Ganiev who reported a method where a DoS attack could lead to RCE.
- Thanks to Karim El Ouerghemmi from RIPS who disclosed a method to store XSS in post slugs.
- Thanks to Slavco for reporting, and confirmation from Karim El Ouerghemmi, a method to bypass protected meta that could lead to arbitrary file deletion.
- Thanks to Erwan LR from WPScan who responsibly disclosed a method that could lead to CSRF.
- And a special thanks to @ zieladam who was integral in many of the releases and patches during this release.
Thank you to all of the reporters for privately disclosing the vulnerabilities . This gave the security team time to fix the vulnerabilities before WordPress sites could be attacked.
Thanks and props!
The 5.5.2 release was led by @whyisjake and the following release squad: @audrasjb , @davidbaumwald , @desrosj , @johnbillion , @metalandcoffee , @noisysocks @planningwrite , @sarahricker and @sergeybiryukov .
In addition to the security researchers and release squad members mentioned above, thank you to everyone who helped make WordPress 5.5.2 happen:
Aaron Jorbin , Alex Concha , Amit Dudhat , Andrey "Rarst" Savchenko , Andy Fragen , Ayesh Karunaratne , bridgetwillard , Daniel Richards , David Baumwald , Davis Shaver , dd32 , Florian TIAR , Hareesh , Hugh Lashbrooke , Ian Dunn , Igor Radovanov , Jake Spurlock , Jb Audras , John Blackbourn , Jonathan Desrosiers , Jon Brown , Joy , Juliette Reinders Folmer , kellybleck , mailnew2ster , Marcus Kazmierczak , Marius L. J. , Milan Dinić , Mohammad Jangda , Mukesh Panchal , Paal Joachim Romdahl , Peter Wilson , Regan Khadgi , Robert Anderson , Sergey Biryukov , Sergey Yakimov , Syed Balkhi , szaqal21 , Tellyworth , Timi Wahalahti , Timothy Jacobs , Towhidul I. Chowdhury , Vinayak Anivase , and zieladam .
- Pentagon Releases Photos and Video of al-Baghdadi Raid
- K-State grants release to women’s hoops player Romero
- Press release: Kalitta Motorsports, Todd to represent SealMaster for 2016 NHRA season
- The Latest: Vatican increases security after Paris attacks
- AP Source: Video addressed to NFL security chief
- NFL denies allegations Rice video was sent to NFL security chief
- Report: Bears told Cowboys of Jeremiah Ratliff’s release for security purposes
- PRESS RELEASE: Final approval given for Circuit of Wales project
- Webb posts 11 luxury watches, 3 cars to secure $10M bond
- Indicted FIFA official Webb securing bond with luxury watches, cars
WordPress 5.5.2 Security and Maintenance Release have 561 words, post on wordpress.org at October 29, 2020. This is cached page on WP Discuss. If you want remove this page, please contact us.