Skip to Main Content

WordPress 4.7.3 Is Now Available

WordPress 4.7.3 is now available. It is strongly recommended that you update your sites to the most current version.

A remote attacker could exploit some of these vulnerabilities to take control of an affected website. WordPress versions 4.7.2 and earlier are affected by these six critical security issues listed below:

  1. Cross-site scripting (XSS) via media file metadata
  2. Control characters can trick redirect URL validation
  3. Unintended files can be deleted by administrators using the plugin deletion functionality
  4. Cross-site scripting (XSS) via video URL in YouTube embeds 
  5. Cross-site scripting (XSS) via taxonomy term names
  6. Cross-site request forgery (CSRF) in Press This leading to excessive use of server resources

For more information, please visit https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/.

Tags