WordPress4.5.2に自動アップデート

このブログでも利用しているブログツール「wordPress」がバージョン4.5.2に自動アップデートされました。
WordPressはマイナーバージョンアップは自動で行なわれます。
そしてこの後日本語版4.5.2へのアップデートを手動で行なうことになるのよね。
今回の修正は複数のセキュリティ問題の修正とのことです。

Version 4.5.2 « WordPress Codex

Summary

From the WordPress 4.5.2 release notes, WordPress versions 4.5.1 and earlier are affected by a SOME vulnerability through Plupload, the third-party library WordPress uses for uploading files. WordPress versions 4.2 through 4.5.1 are vulnerable to reflected XSS using specially crafted URIs through MediaElement.js, the third-party library used for media players. MediaElement.js and Plupload have also released updates fixing these issues.

Both issues were analyzed and reported by Mario Heiderich, Masato Kinugawa, and Filedescriptor from Cure53. Thanks to the team for practicing responsible disclosure, and to the Plupload and MediaElement.js teams for working closely with us to coördinate and fix these issues.

 

コメントを残す