Skip to content

Version 6.8.11

Choose a tag to compare

@wordpress-packager wordpress-packager released this 06 Oct 17:50
eb3d108

Sourced from WordPress.org Documentation.

Summary

Security updates

This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

As a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.