{"id":43194,"date":"2021-09-09T12:11:37","date_gmt":"2021-09-09T03:11:37","guid":{"rendered":"https:\/\/jirak.net\/wp\/wordpress-5-8-1-security-and-maintenance-release\/"},"modified":"2021-09-09T12:34:02","modified_gmt":"2021-09-09T03:34:02","slug":"wordpress-5-8-1-security-and-maintenance-release","status":"publish","type":"post","link":"https:\/\/jirak.net\/wp\/wordpress-5-8-1-security-and-maintenance-release\/","title":{"rendered":"WordPress 5.8.1 Security and Maintenance Release"},"content":{"rendered":"<p>WordPress 5.8.1 Security and Maintenance Release<\/p>\n<p>WordPress 5.8.1 is now available!<\/p>\n<p>This security and maintenance release features <a href=\"https:\/\/core.trac.wordpress.org\/query?milestone=5.8.1&amp;group=component&amp;col=id&amp;col=summary&amp;col=milestone&amp;col=owner&amp;col=type&amp;col=status&amp;col=priority&amp;order=priority\">60 bug<\/a> <a href=\"https:\/\/github.com\/WordPress\/gutenberg\/pull\/34393\">fixes<\/a> in addition to 3 security fixes. Because this is a <strong>security release<\/strong>, it is recommended that you update your sites immediately. All versions since WordPress 5.4 have also been updated.<\/p>\n<p>WordPress 5.8.1 is a short-cycle security and maintenance release. The next major release will be version <a href=\"https:\/\/make.wordpress.org\/core\/5-9\/\">5.9<\/a>.<\/p>\n<p>You can download WordPress 5.8.1 by downloading from WordPress.org, or visit your Dashboard \u2192 Updates and click Update Now.<\/p>\n<p>If you have sites that support automatic background updates, they\u2019ve already started the update process.<\/p>\n<h3><strong>Security Updates<\/strong><\/h3>\n<p>3 security issues affect WordPress versions between 5.4 and 5.8. If you haven\u2019t yet updated to 5.8, all WordPress versions since 5.4 have also been updated to fix the following security issues:<\/p>\n<ul>\n<li>Props <a href='https:\/\/profiles.wordpress.org\/mdawaffe\/' class='mention'><span class='mentions-prefix'>@<\/span>mdawaffe<\/a>, member of the WordPress Security Team for their work fixing a data exposure vulnerability within the REST API.<\/li>\n<li>Props to Micha\u0142 Bentkowski of Securitum for reporting a XSS vulnerability in the block editor.<\/li>\n<li>The Lodash library has been updated to version 4.17.21 in each branch to incorporate upstream security fixes.<\/li>\n<\/ul>\n<p>In addition to these issues, the security team would like to thank the following people for reporting vulnerabilities during the WordPress 5.8 beta testing period, allowing them to be fixed prior to release:<\/p>\n<ul>\n<li>Props <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/evanricafort.com\/\">Evan Ricafort<\/a>&nbsp;for reporting a XSS vulnerability in the block editor discovered during the 5.8 release\u2019s beta period.<\/li>\n<li>Props <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/profiles.wordpress.org\/stevehenty\/\">Steve Henty<\/a>&nbsp;for reporting a privilege escalation issue in the block editor.<\/li>\n<\/ul>\n<p>Thank you to all of the reporters for <a href=\"https:\/\/make.wordpress.org\/core\/handbook\/testing\/reporting-security-vulnerabilities\/\">privately disclosing the vulnerabilities<\/a>. This gave the WordPress security team time to fix the vulnerabilities before WordPress sites could be attacked.<\/p>\n<p>For more information, browse the <a href=\"https:\/\/core.trac.wordpress.org\/query?milestone=5.8.1&amp;group=component&amp;col=id&amp;col=summary&amp;col=milestone&amp;col=owner&amp;col=type&amp;col=status&amp;col=priority&amp;order=priority\">full list of changes<\/a> on Trac, or check out the <a href=\"https:\/\/wordpress.org\/support\/wordpress-version\/version-5-8-1\/\">version 5.8.1 HelpHub documentation page<\/a>.<\/p>\n<h2>Thanks and props!<\/h2>\n<p>The 5.8.1 release was led by <a href=\"https:\/\/profiles.wordpress.org\/desrosj\/\">Jonathan Desrosiers<\/a> and <a href=\"https:\/\/profiles.wordpress.org\/circlecube\/\">Evan Mullins<\/a>.<\/p>\n<p>In addition to the security researchers and release squad members mentioned above, thank you to everyone who helped make WordPress 5.8.1 happen:<\/p>\n<p><a href=\"https:\/\/profiles.wordpress.org\/2linctools\/\">2linctools<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/zieladam\/\">Adam Zielinski<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/schlessera\/\">Alain Schlesser<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ajlende\/\">Alex Lende<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/alexstine\/\">alexstine<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/algala\/\">AlGala<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/oandregal\/\">Andr\u00e9<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/andraganescu\/\">Andrei Draganescu<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/azaozz\/\">Andrew Ozz<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ankitmaru\/\">Ankit Panchal<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/antpb\/\">Anthony Burchell<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/antonvlasenko\/\">Anton Vlasenko<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/aristath\/\">Ari Stathopoulos<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ribaricplusplus\/\">Bruno Ribaric<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/poena\/\">Carolina Nymark<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/daisyo\/\">Daisy Olsen<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/talldanwp\/\">Daniel Richards<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/dariak\/\">Daria<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/davidanderson\/\">David Anderson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/davidbinda\/\">David Bi\u0148ovec<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/dlh\/\">David Herrera<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ocean90\/\">Dominik Schilling<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ellatrix\/\">Ella van&nbsp;Durpe<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/enchiridion\/\">Enchiridion<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/circlecube\/\">Evan Mullins<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/garyj\/\">Gary Jones<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mamaduka\/\">George Mamadashvili<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/gziolo\/\">Greg Zi\u00f3\u0142kowski<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/priethor\/\">H\u00e9ctor Prieto<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ianmjones\/\">ianmjones<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/audrasjb\/\">Jb Audras<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jblz\/\">Jeff Bowen<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/joedolson\/\">Joe Dolson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/joen\/\">Joen A.<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/johnbillion\/\">John Blackbourn<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/desrosj\/\">Jonathan Desrosiers<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/juanmaguitar\/\">JuanMa Garrido<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jrf\/\">Juliette Reinders Folmer<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/kevin940726\/\">Kai Hao<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/kapilpaul\/\">Kapil Paul<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/gwwar\/\">Kerry Liu<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/kevinfodness\/\">Kevin Fodness<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mkaz\/\">Marcus Kazmierczak<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mark-k\/\">Mark-k<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mhuntdesign\/\">Matt<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mdawaffe\/\">Michael Adams (mdawaffe)<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mikeschroder\/\">Mike Schroder<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/moch11\/\">moch11<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mukesh27\/\">Mukesh Panchal<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ntsekouras\/\">Nik Tsekouras<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/paaljoachim\/\">Paal Joachim Romdahl<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/swissspidy\/\">Pascal Birchler<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/pbearne\/\">Paul Bearne<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/pbiron\/\">Paul Biron<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/peterwilsoncc\/\">Peter Wilson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/walbo\/\">Petter Walb\u00f8 Johnsg\u00e5rd<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/radixweb\/\">Radixweb<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/rtm909\/\">Rahul Mehta<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ramonopoly\/\">ramonopoly<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ravipatel\/\">ravipatel<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/youknowriad\/\">Riad Benguella<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/noisysocks\/\">Robert Anderson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/kreppar\/\">Rodrigo Arias<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/sanketchodavadiya\/\">Sanket Chodavadiya<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/sergeybiryukov\/\">Sergey Biryukov<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/sabernhardt\/\">Stephen Bernhardt<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/netweb\/\">Stephen Edgar<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/stevehenty\/\">Steve Henty<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/terraling\/\">terraling<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/timothyblynjacobs\/\">Timothy Jacobs<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/tmatsuur\/\">tmatsuur<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/tobiasbg\/\">TobiasBg<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/hellofromTonya\/\">Tonya Mork<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/toro_unit\/\">Toro_Unit (Hiroshi Urabe)<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/vladytimy\/\">Vlad T<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/wb1234\/\">wb1234<\/a>, and <a href=\"https:\/\/profiles.wordpress.org\/wfmattr\/\">WFMattR<\/a>.<br \/>\nSource: <a href=\"https:\/\/wordpress.org\/news\/2021\/09\/wordpress-5-8-1-security-and-maintenance-release\/\" target=\"_blank\" rel=\"noopener\">WordPress 5.8.1 Security and Maintenance Release<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\"><p>WordPress 5.8.1 Security and Maintenance Release WordPress 5.8.1 is now available! This security and maintenance release features 60 bug fixes in addition to 3 security fixes. Because this is a security release, it is recommended that you update your sites immediately. All versions since WordPress 5.4 have also been updated. WordPress 5.8.1 is a short-cycle security and maintenance release. The next major release will be version 5.9. You can download WordPress 5.8.1 by downloading from WordPress.org, or visit your Dashboard \u2192 Updates and click Update Now. If you have sites that support automatic background updates, they\u2019ve already started the update process. Security Updates 3 security issues affect WordPress versions between 5.4 and 5.8. If you haven\u2019t yet updated to 5.8, all WordPress versions since 5.4 have also been updated to fix the following security issues: Props @mdawaffe, member of the <a class=\"mh-excerpt-more\" href=\"https:\/\/jirak.net\/wp\/wordpress-5-8-1-security-and-maintenance-release\/\" title=\"WordPress 5.8.1 Security and Maintenance Release\">[ more&#8230; ]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[169],"tags":[395],"class_list":["post-43194","post","type-post","status-publish","format-standard","hentry","category-news","tag-wordpress"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/43194","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/comments?post=43194"}],"version-history":[{"count":1,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/43194\/revisions"}],"predecessor-version":[{"id":43195,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/43194\/revisions\/43195"}],"wp:attachment":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/media?parent=43194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/categories?post=43194"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/tags?post=43194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}