Menu Close

WordPress Version 4.7.5 released addressing security risks

WordPress releases WordPress version 4.7.5 to address 6 security vulnerabilities

The recent ransomware attack that took place last week could have been avoided for many computers had a recent software patch been installed. Last week’s attack used an NSA exploit codnamed ETERNALBLUE, a software weapon that allowed the spy agency’s hackers to break into any of millions of Windows computers.

In March 2017, Microsoft released a software update that addresses a flaw in a certain version of Windows software that governs how networked computers shares files and print.

WordPress is the World’s most popular content management system (CMS) powering over 25% of the websites online. As a result, hackers actively seek out WordPress sites to attack.

One of the best ways to prevent an attack is to update your computer to install software updates as soon as they are released. WordPress just released WordPress version 4.7.5 that addresses six security issues. As a result, I strongly recommend that you download and install the latest version of WordPress.

WordPress security vulnerabilities

WordPress version 4.7.4 and earlier have six security issues:

  1. Improper handling of post meta data values in the XML-RPC API.
  2. Insufficient redirect validation in the HTTP class.
  3. A Cross Sites Request Forgery (CRSF) vulnerability was discovered in the filesystem credentials dialog.
  4. Lack of capability checks for post meta data in the XML-RPC API.
  5. A cross-site scripting (XSS) vulnerability was discovered related to the Customizer.
  6. A cross-site scripting (XSS) vulnerability was discovered when attempting to upload very large files.

In addition to the security issues reported above, WordPress version 4.7.5 contains three maintenance fixes.

Download version 4.7.5 or go to the dashboard on your website and click ‘update now’. Sites that support background updates are updating to WordPress 4.7.5 already.

We will keep you posted when yet another WordPress update or news comes out that you need to know about.  In the meantime, download WordPress version 4.7.5.

1 Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

CALL ME LOKALYZ