Skip to content

Version 7.0.2

Latest

Choose a tag to compare

@wordpress-packager wordpress-packager released this 17 Jul 19:09
eb3d108

Sourced from WordPress.org Documentation.

Summary

Security updates

This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:

  • A facilitated SQL injection issue reported by as a team by TF1T, dtro, and haongo
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber

As a courtesy, these fixes are available in affected branches of WordPress to eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported.