WordPress 5.0.1 Security Release
WordPress 5.0.1 Security Release WordPress 5.0.1 is now available. This is a security release for all versions since WordPress 3.7. We strongly encourage you to update your sites immediately. Plugin authors are encouraged to read the 5.0.1 developer notes for information on backwards-compatibility. WordPress versions 5.0 and earlier are affected by the following bugs, which are fixed in version 5.0.1. Updated versions of WordPress 4.9 and older releases are also available, for users who have not yet updated to 5.0. Karim El Ouerghemmi discovered that authors could alter meta data to delete files that they weren’t authorized to. Simon Scannell of RIPS Technologies discovered that authors could create posts of unauthorized post types with specially crafted input. Sam Thomas discovered that contributors could craft meta data in a way that resulted in PHP object injection. Tim Coen discovered that contributors [ more… ]