v4.7.1 - Security & Test Fixes
Security
- Bumped
guzzlehttp/guzzle(7.10.5 → 7.15.1) andguzzlehttp/psr7(2.10.4 → 2.13.0), resolving 3 medium-severity advisories:- Silent HTTPS-proxy downgrade to cleartext
- CRLF injection in HTTP start-line serialization
- Dot-only cookie domains matching all hosts
Fixes
- Fixed a stale URL in
SiteContentScopingTest(multisite plugin settings page is registered atmultisite-settings, notsite-settings) — test-only, no runtime behavior change.
No new features in this release. Follows up on v4.7.0.