Version 7.0.5
Sourced from WordPress.org Documentation.
Summary
Security updates
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
- An issue allowing a crafted URL to install and preview a theme from WordPress.org reported by Paulos Yibelo and pwn.ai
- A stored cross-site scripting (XSS) issue in custom header images on some themes reported by Jeremy Felt of the WordPress Security Team
- An information disclosure issue exposing the title of a private parent post reported by HDWSec
- An HTML API issue allowing modified text to break out of an HTML comment reported by Jeremy Felt of the WordPress Security Team
- A multisite issue allowing a site administrator to network-activate a network-only plugin reported by Jesse McNeil
- A Contributor+ arbitrary post overwrite issue reported by Anthropic
- An authenticated path traversal issue in the REST API templates controller reported by Anthropic
- An authorization issue allowing any authenticated user to reparent comments, including notes, reported by viridis
- An XML-RPC issue allowing changeset posts to bypass the custom CSS capability check reported by Ben Bidner of the WordPress Security Team
- A Contributor+ disclosure of draft and pending post slugs reported by hermanhms
- An unauthenticated stored cross-site scripting (XSS) issue via paragraph formatting, subject to comment approval, reported by Rafie Muhammad (Awesome Motive, Inc.)