Payment Plans Now Available

+44 208 123 3380

  • Home
  • Design
    • Website Design Services
    • Ecommerce Solutions
    • VC & Data Design
    • Tailored AI & LLM Services
  • Marketing
    • Digital Marketing – Step by Step Overview
    • Digital Marketing Management
    • SEO – Search Engine Optimisation
    • Adwords & Facebook PPC
    • Social Media Management
  • Portfolio
    • Testimonials & Reviews
  • Contact
  • A/C
    • Login
Product has been added to your basket.
Blog

WordPress 4.8.2 – Security & Maintenance Update

Final Design
Wordpress
Security & Maintenance
WordPress 4.8.2 – Security & Maintenance Update
Security & Maintenance
8 years ago

WordPress released a security and maintenance update today – version 4.8.2, so all Final Design Studios Clients should have received an email notification that this has automatically taken place.

If you have not received an email notifying you of this security update, please get in touch with us and we will get you organised. Call 0203 608 6609 today. 

Alternatively, log into your WordPress dashboard and hover your mouse over the DASHBOARD link in the left-hand navigation bar, where you will be presented with a pop-up menu listing UPDATES as one of its items. Click UPDATES then follow the on-screen instructions.

The security update was deployed to address the following issues:

  1. $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi). WordPress core is not directly vulnerable to this issue, but we’ve added hardening to prevent plugins and themes from accidentally causing a vulnerability. Reported by Slavco
  2. A cross-site scripting (XSS) vulnerability was discovered in the oEmbed discovery. Reported by xknown of the WordPress Security Team.
  3. A cross-site scripting (XSS) vulnerability was discovered in the visual editor. Reported by Rodolfo Assis (@brutelogic) of Sucuri Security.
  4. A path traversal vulnerability was discovered in the file unzipping code. Reported by Alex Chapman (noxrnet).
  5. A cross-site scripting (XSS) vulnerability was discovered in the plugin editor. Reported by 陈瑞琦 (Chen Ruiqi).
  6. An open redirect was discovered on the user and term edit screens. Reported by Yasin Soliman (ysx).
  7. A path traversal vulnerability was discovered in the customizer. Reported by Weston Ruter of the WordPress Security Team.
  8. A cross-site scripting (XSS) vulnerability was discovered in template names. Reported by Luka (sikic).
  9. A cross-site scripting (XSS) vulnerability was discovered in the link modal. Reported by Anas Roubi (qasuar).

To read more details, please visit https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/ 

 

 

You must be logged in to post a comment.
Previous Post
Top 37 FREE UK Business Directories
Next Post
Google Search Generative Experience (SGE): A Game Changer for Businesses
No results found.

Web Design Services from £595

Learn More >

Recent Posts

  • Google Search Generative Experience (SGE): A Game Changer for Businesses
  • WordPress 4.8.2 – Security & Maintenance Update
  • Top 37 FREE UK Business Directories
  • Free Dialup Internet Connection Numbers
  • Affiliate Marketing for Dummies
Top 37 FREE UK Business Directories
Google Search Generative Experience (SGE): A Game Changer for Businesses
Final Design Studios Icon in Glass
Final Design Studios - Web Design & SEO Services
Facebook
Google
LinkedIn
Yelp
RSS

"A real personal service that is pretty hard
to find these days. Excellent!" More Reviews

  • Home
    • Web Design Services
    • Ecommerce Development
    • Web Design Packages & Fees
    • Tailored AI & LLM Services
  • Digital Marketing Services
    • Digital Marketing Management Services
    • SEO & Content Marketing Services
    • Social Media Management Services
  • Insights
  • Login

THINK BIG

Send us some details along with your contact details and we’ll get right back to you.

or call 0208 123 3380

Fill out this field
Fill out this field
Please enter a valid email address.
Fill out this field

© Final DESIGN Studios – UK Web Consultant & Internet Marketing Services Since 1999 – All rights reserved.

By using this website, you agree to its use of cookies for the purposes of providing an improved user experience.