WordPress 4.0.1 Security Release

WordPress 4.0.1 Security Release

WordPress 4.0.1 is now available. This is a critical security release for all previous versions and we strongly encourage you to update your sites immediately.

Sites that support automatic background updates will be updated to WordPress 4.0.1 within the next few hours. If you are still on WordPress 3.9.2, 3.8.4, or 3.7.4, you will be updated to 3.9.3, 3.8.5, or 3.7.5 to keep everything secure. (We don’t support older versions, so please update to 4.0.1 for the latest and greatest.)

WordPress versions 3.9.2 and earlier are affected by a critical cross-site scripting vulnerability, which could enable anonymous users to compromise a site. This was reported by Jouko Pynnonen. This issue does not affect version 4.0, but version 4.0.1 does address these eight security issues:

  • Three cross-site scripting issues that a contributor or author could use to compromise a site. Discovered by Jon Cave, Robert Chapin, and John Blackbourn of the WordPress security team.
  • A cross-site request forgery that could be used to trick a user into changing their password.
  • An issue that could lead to a denial of service when passwords are checked. Reported by Javier Nieto Arevalo and Andres Rojas Guerrero.
  • Additional protections for server-side request forgery attacks when WordPress makes HTTP requests. Reported by Ben Bidner (vortfu).
  • An extremely unlikely hash collision could allow a user’s account to be compromised, that also required that they haven’t logged in since 2008 (I wish I were kidding). Reported by David Anderson.
  • WordPress now invalidates the links in a password reset email if the user remembers their password, logs in, and changes their email address. Reported separately by Momen Bassel, Tanoy Bose, and Bojan Slavković of ManageWP.

Version 4.0.1 also fixes 23 bugs with 4.0, and we’ve made two hardening changes, including better validation of EXIF data we are extracting from uploaded photos. Reported by Chris Andrè Dale.

We appreciated the responsible disclosure of these issues directly to our security team. For more information, see the release notes or consult the list of changes.

Download WordPress 4.0.1 or venture over to Dashboard → Updates and simply click “Update Now”.

Already testing WordPress 4.1? The second beta is now available (zip) and it contains these security fixes. For more on 4.1, see the beta 1 announcement post.

WordPress 4.0.1 Download link: https://wordpress.org/download/

Free wordpress Theme

10 comments to “WordPress 4.0.1 Security Release”

You can leave a reply or Trackback this post.
  1. boom beach hack says: February 10, 2015 at 8:44 pm

    What’s up, just wanted to mention, I enjoyed this blog post.
    It was helpful. Keep on posting!

  2. تبلیغات در وایبر says: March 18, 2015 at 12:15 pm

    سلام سایت خوبی دارید با تشکر از سایت خوبتون واقعا عالیه!لطفا به سایت منم سری بزنید ارسال تبلیغات در وایبر به صورت رایگان و روزانه تا سقف10.000.000عددا

  3. قیمت طراحی سایت says: May 3, 2015 at 4:20 pm

    Having read this I thought it was extremely enlightening.

    I appreciate you taking the time and energy to put this
    informative article together. I once again find myself personally spending a
    significant amount of time both reading and commenting.
    But so what, it was still worthwhile!

  4. طراحی سایت says: August 12, 2015 at 2:11 pm

    I go to see everyday some sites and blogs to read content, however this website presents quality based posts.

  5. Make App Free says: August 21, 2015 at 1:41 am

    Hi to every single one, it’s in fact a nice for me to pay a quick visit this website,
    it includes useful Information.

  6. quest bars says: August 21, 2015 at 8:46 am

    Appreciation to my father who stated to me concerning this blog,
    this weblog is really amazing.

  7. web development belfast says: August 23, 2015 at 4:13 pm

    magnificent issues altogether, you simply gained a new reader.
    What would you recommend about your publish that you simply made a few days in the past?

    Any positive?

  8. quest bars says: August 26, 2015 at 7:24 pm

    Hello, every time i used to check webpage posts here in the early hours in the break of
    day, for the reason that i love to gain knowledge of more and more.

Write a Reply or Comment

Your email address will not be published.