Retraceur 4.3.0: security release

Publié le

dans

.

Many thanks to the WordPress® contributors for publishing, a bit more than 24 hours ago, the software’s 7.0.5 release: a security update fixing several vulnerabilities. Retraceur is a fork, these fixes don’t land automatically: I backported them to the 4.0 branch & the 4.3.0 release this evening.

Updating is strongly recommended for all Retraceur 4.0 sites.

Fixes included in this release:

  • A capability-check bypass on post creation (a supplied post ID on the create path allowed overwriting existing content).
  • A path traversal issue in block template file resolution.
  • A missing capability check on the sample-permalink Ajax action.
  • Disclosure of an inaccessible parent post’s title in the media sidebar.
  • A jQuery selector injection issue in the admin theme installer preview.
  • A missing capability check when Ajax-activating a network-only plugin on multisite.
  • An overly permissive regex in wpautop() that could let a paragraph tag land inside a <blockquote> attribute.

Fixes related to the Customizer, the XML-RPC API and Comments were not included, as these features are not supported by Retraceur Cœur.

No active exploitation is currently known, but as with any security release, updating promptly is recommended.

Featured photo : Sebastian on Unsplash

Note: The WordPress® trademark is the intellectual property of the WordPress® Foundation. The use of the WordPress® name in this article is for identification purposes only and does not imply endorsement by the WordPress® Foundation.