The WordPress core team do a great job of releasing maintenance and security patches regularly. They’ve done it again!
WordPress 4.3.1 Security and Maintenance Release Available!
PSA from the WordPress core team:
WordPress 4.3.1 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately.
This release addresses three issues, including two cross-site scripting vulnerabilities and a potential privilege escalation.
- WordPress versions 4.3 and earlier are vulnerable to a cross-site scripting vulnerability when processing shortcode tags (CVE-2015-5714). Reported by Shahar Tal and Netanel Rubin of Check Point.
- A separate cross-site scripting vulnerability was found in the user list table. Reported by Ben Bidner of the WordPress security team.
- Finally, in certain cases, users without proper permissions could publish private posts and make them sticky (CVE-2015-5715). Reported by Shahar Tal and Netanel Rubin of Check Point.
We highly suggest you get all of your sites updated immediately! Visit the official WordPress Release Post for more information.
If you’re short on time or don’t have the resources to get your updates done, no worries! Please contact us here at Maintainn, we will maintain your WordPress investment.