Just a few hours after WordPress® 7.0.4 was released, here’s Retraceur 4.2.0.
This new version does not introduce a new feature. It does something much more essential: keeping the software secure.
A new security fix
WordPress 7.0.4, released on August 12, fixes in particular a Remote Code Execution (RCE) vulnerability that can be exploited through the upload of a malicious file. This vulnerability affects sites using Imagick and Ghostscript and requires the attacker to have an authenticated account with permissions equivalent to at least the Author role.
The security fix has therefore been integrated into the Retraceur codebase, and version 4.2.0 is now available.
Thanks to those who contribute to open source security
Even though Retraceur now follows its own path, I continue to pay close attention to the security work carried out by the people contributing to the software it originated from.
This is also what open source is about: being able to retrace a different path while continuing to benefit from the work, expertise, and vigilance of those who contribute to making free and open source software better.
Also, thank you to everyone who continues to follow and support Retraceur.
Featured photo : Tom Delanoue on Unsplash
Note: The WordPress® trademark is the intellectual property of the WordPress Foundation. The use of the WordPress® name in this article is for identification purposes only and does not imply endorsement by the WordPress Foundation.


Conversation
Rejoignez la conversation depuis Bluesky