WordPress 5.4.2 Security and Maintenance Release

WordPress 5.4.2 Security and Maintenance Release

WordPress 5.4.2 is available for security and maintenance!

To keep the security and performance of WordPress, the team regularly updates with new features, bug fixes and improvements.

In this article, we will give you some notes about new features of WordPress 5.4.2 and some best  WordPress themes ready for this new update.

And now, let’s started!


What’s new in WordPress 5.4.2?

This security and maintenance release features 23 fixes and enhancements. Plus, it adds a number of security fixes—see the list below.

These bugs affect WordPress versions 5.4.1 and earlier; version 5.4.2 fixes them, so you’ll want to upgrade.

If you haven’t yet updated to 5.4, there are also updated versions of 5.3 and earlier that fix the bugs for you.

Security Updates

WordPress versions 5.4 and earlier are affected by the following bugs, which are fixed in version 5.4.2. If you haven’t yet updated to 5.4, there are also updated versions of 5.3 and earlier that fix the security issues.

  • Props to Sam Thomas (jazzy2fives) for finding an XSS issue where authenticated users with low privileges are able to add JavaScript to posts in the block editor.
  • Props to Luigi – (gubello.me) for discovering an XSS issue where authenticated users with upload permissions are able to add JavaScript to media files.
  • Props to Ben Bidner of the WordPress Security Team for finding an open redirect issue in wp_validate_redirect().
  • Props to Nrimo Ing Pandum for finding an authenticated XSS issue via theme uploads.
  • Props to Simon Scannell of RIPS Technologies for finding an issue where set-screen-option can be misused by plugins leading to privilege escalation.
  • Props to Carolina Nymark for discovering an issue where comments from password-protected posts and pages could be displayed under certain conditions.

One maintenance update was also deployed to versions 5.1, 5.2 and 5.3. See the related developer note for more information.

You can browse the full list of changes on Trac.

For more info, browse the full list of changes on Trac or check out the Version 5.4.2 documentation page.


How to Update Your Site to WordPress 5.4.2

You can download WordPress 5.4.2 from the button at the top of this page, or visit your Dashboard → Updates and click Update Now.

If you have sites that support automatic background updates, they’ve already started the update process.


Our themes & WordPress 5.4.2

Currently, all our WordPress themes are compatible with WordPress 5.4.1. Due to the security and maintenance update, all of them should be compatible with WordPress 5.4.2 and you can update it normally in your site. We also plan to update all of our WordPress themes for this release in the coming time.

See Our Best-selling WordPress Themes 2020:

 

 

 

 

 

 

 

 

 


See our theme collections:

Best selling multi vendor wordpress themes

 Best Selling Multi Vendor MarketPlace WordPress Themes

You might also like

Leave Your Comment

Quà Tết Cao Cấp Hộp quà tết Giỏ quà tết Túi quà tết