Skip to content

Version 7.0.4

Choose a tag to compare

@wordpress-packager wordpress-packager released this 12 Aug 15:18
eb3d108

Sourced from WordPress.org Documentation.

Summary

Security updates

This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:

  • An authenticated Author+ remote code execution issue via malicious file upload on sites that use Imagick and Ghostscript reported by the team at pwn.ai

As a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.

  • WordPress 6.9 is affected by this vulnerability. Version 6.9.7 has been released containing a fix.
  • WordPress 6.8 is affected by this vulnerability. Version 6.8.8 has been released containing a fix.
  • WordPress 6.7 is affected by this vulnerability. Version 6.7.7 has been released containing a fix.
  • WordPress 6.6 is affected by this vulnerability. Version 6.6.7 has been released containing a fix.
  • WordPress 6.5 is affected by this vulnerability. Version 6.5.10 has been released containing a fix.
  • WordPress 6.4 is affected by this vulnerability. Version 6.4.10 has been released containing a fix.
  • WordPress 6.3 is affected by this vulnerability. Version 6.3.10 has been released containing a fix.
  • WordPress 6.2 is affected by this vulnerability. Version 6.2.11 has been released containing a fix.
  • WordPress 6.1 is affected by this vulnerability. Version 6.1.12 has been released containing a fix.
  • WordPress 6.0 is affected by this vulnerability. Version 6.0.14 has been released containing a fix.
  • WordPress 5.9 is affected by this vulnerability. Version 5.9.16 has been released containing a fix.
  • WordPress 5.8 is affected by this vulnerability. Version 5.8.15 has been released containing a fix.
  • WordPress 5.7 is affected by this vulnerability. Version 5.7.17 has been released containing a fix.
  • WordPress 5.6 is affected by this vulnerability. Version 5.6.19 has been released containing a fix.
  • WordPress 5.5 is affected by this vulnerability. Version 5.5.20 has been released containing a fix.
  • WordPress 5.4 is affected by this vulnerability. Version 5.4.21 has been released containing a fix.
  • WordPress 5.3 is affected by this vulnerability. Version 5.3.23 has been released containing a fix.
  • WordPress 5.2 is affected by this vulnerability. Version 5.2.26 has been released containing a fix.
  • WordPress 5.1 is affected by this vulnerability. Version 5.1.24 has been released containing a fix.
  • WordPress 5.0 is affected by this vulnerability. Version 5.0.27 has been released containing a fix.
  • WordPress 4.9 is affected by this vulnerability. Version 4.9.31 has been released containing a fix.
  • WordPress 4.8 is affected by this vulnerability. Version 4.8.30 has been released containing a fix.
  • WordPress 4.7 is affected by this vulnerability. Version 4.7.35 has been released containing a fix.
  • WordPress 4.6 and earlier no longer receive security updates.