Retraceur 4.5.0: security and maintenance release

Publié le

dans

.

A new security release of Retraceur is now available.

Just a few hours after the release of WordPress® 7.1.3, I integrated the security and maintenance fixes included in this new release of the software Retraceur is derived from.

Retraceur 4.5.0 includes the 5 security fixes and 3 bug fixes delivered in WordPress® 7.1.3.

These fixes address, among other things:

  • a denial-of-service issue in WP_Http::make_absolute_url();
  • a second-order SQL injection in WXR exports;
  • a weakness allowing Author-role users to sticky posts;
  • an XSS vulnerability in Imgur embeds;
  • a possible action-name collision through parameters passed to {status}_{type} hooks.

As with every security release, I strongly recommend updating your site as soon as possible.

Retraceur continues on its own path

This release once again illustrates one of Retraceur’s defining principles: the project continues to build on the work contributed to WordPress whenever that work remains consistent with its goals.

This approach makes it possible to benefit from the considerable security work carried out by WordPress contributors while continuing, independently, along the path traced by Retraceur. Thank you to all the contributors who identified, investigated, and fixed these security issues in the project Retraceur is derived from.

Featured photo : Kseniia Lobko on Unsplash

Note: The WordPress® trademark is the intellectual property of the WordPress® Foundation. The use of the WordPress® name in this article is for identification purposes only and does not imply endorsement by the WordPress® Foundation.