Elemental Holdings, Inc. A South Florida Graphic Design Firm
  • ENGAGE
  • CULTURE
  • CASE STUDIES
  • SOLUTIONS
  • COMMUNICATE
  • DISCOVER
  • Menu Menu

WordPress 4.1.2 Security Release

2015/04/21/0 Comments/in News, WordPress/by Bruce Quiroz
Posted April 21, 2015 by Gary Pendergast. Filed under Releases, Security.

WordPress 4.1.2 is now available. This is a critical security release for all previous versions and we strongly encourage you to update your sites immediately.

WordPress versions 4.1.1 and earlier are affected by a critical cross-site scripting vulnerability, which could enable anonymous users to compromise a site. This was reported by Cedric Van Bockhaven and fixed by Gary Pendergast, Mike Adams, andAndrew Nacin of the WordPress security team.

We also fixed three other security issues:

  • In WordPress 4.1 and higher, files with invalid or unsafe names could be uploaded. Discovered by Michael Kapfer and Sebastian Kraemer of HSASec.
  • In WordPress 3.9 and higher, a very limited cross-site scripting vulnerability could be used as part of a social engineering attack. Discovered by Jakub Zoczek.
  • Some plugins were vulnerable to an SQL injection vulnerability. Discovered by Ben Bidner of the WordPress security team.

We also made four hardening changes, discovered by J.D. Grimes, Divyesh Prajapati,Allan Collins and Marc-Alexandre Montpas.

We appreciated the responsible disclosure of these issues directly to our security team. For more information, see the release notes or consult the list of changes.

Download WordPress 4.1.2 or venture over to Dashboard → Updates and simply click “Update Now.” Sites that support automatic background updates are already beginning to update to WordPress 4.1.2.

Thanks to everyone who contributed to 4.1.2: Allan Collins, Alex Concha, Andrew Nacin, Andrew Ozz, Ben Bidner, Boone Gorges, Dion Hulse, Dominik Schilling, Drew Jaynes, Gary Pendergast, Helen Hou-Sandí, John Blackbourn, and Mike Adams.

A number of plugins also released security fixes yesterday. Keep everything updated to stay secure. If you’re a plugin author, please read this post to confirm that your plugin is not affected by the same issue. Thank you to all of the plugin authors who worked closely with our security team to ensure a coordinated response.

Already testing WordPress 4.2? The third release candidate is now available (zip) and it contains these fixes. For more on 4.2, see the RC 1 announcement post.

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://elementalstudios.us/wp-content/uploads/2015/04/Wordpress-Wallpapers-for-Bloggers-5.png 542 964 Bruce Quiroz https://elementalstudios.us/wp-content/uploads/2016/09/logo_es_nav-1.png Bruce Quiroz2015-04-21 15:07:322015-04-21 15:07:32WordPress 4.1.2 Security Release
0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search Search

Recent Posts

  • Wordfence 7.8.0 Is Out! Here Is What Is Included
  • Patch Now: The WordPress 6.0.3 Security Update Contains Important Fixes
  • Wordfence 7.7
  • You Don’t Need to Be a Magician to Optimize SEO
  • Meta is building VR gloves for the metaverse

Categories

  • Apps
  • Business
  • Colors
  • E-Commerce
  • Frontpage Article
  • Graphic Design
  • Graphic Design Firm
  • Internet News
  • Internet Speed
  • Marketing
  • News
  • Printing
  • Privacy
  • Psychology
  • Security
  • SEO
  • Social Media
  • Technology
  • Typography
  • WordPress

Recent Comments

    Archives

    • November 2022
    • October 2022
    • January 2022
    • November 2021
    • October 2021
    • August 2021
    • April 2021
    • June 2020
    • May 2020
    • March 2020
    • February 2020
    • October 2019
    • September 2019
    • July 2019
    • May 2019
    • April 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • September 2018
    • July 2018
    • June 2018
    • May 2018
    • March 2018
    • October 2017
    • November 2016
    • October 2016
    • September 2016
    • August 2016
    • April 2016
    • March 2016
    • February 2016
    • January 2016
    • August 2015
    • June 2015
    • May 2015
    • April 2015
    • March 2015
    • November 2014
    • October 2014
    • July 2014
    • April 2014
    • March 2014
    • February 2014
    • December 2013
    © Copyright - Elemental Holdings, Inc. A South Florida Graphic Design Firm || "We Share your Dreams with the World" || Contact us today via phone or e-mail || info@elementalstudios.us || T. 954.586.4410
    • Link to Facebook
    • Link to Behance
    • Link to X
    • Link to Instagram
    • Link to Youtube
    • Link to Rss this site
    • Link to Mail
    • Link to 500px
    Link to: 4 Tips For Hiring The Right SEO Firm Link to: 4 Tips For Hiring The Right SEO Firm 4 Tips For Hiring The Right SEO Firm Link to: Android M Is Here, and So Is Google’s Smartphone Future Link to: Android M Is Here, and So Is Google’s Smartphone Future Android M Is Here, and So Is Google’s Smartphone Future
    Scroll to top Scroll to top Scroll to top