首页 网站建设 Wordpress 浏览内容
WordPress 4.7.2发布修复三处安全问题
从WordPress的4.7.2发布后:WordPress的版本4.7.1及更早版本由三个安全问题的影响:
1.用于在新闻中分配分类术语的用户界面向没有权限使用它的用户显示。
2.WP_Query在传递不安全数据时容易受到SQL注入(SQLi)的攻击。WordPress核心不是直接容易受到这个问题,但我们已经添加了强化,以防止插件和主题意外导致一个漏洞。
3.在帖子列表表中发现了跨站点脚本(XSS)漏洞。
从另外的4.7.2的安全性信息披露,在WordPress 4.7.0和4.7.1版本是受以下安全问题:
1.有一个在一个REST API端点未经验证的特权提升漏洞。
要下载的WordPress 4.7.2,从仪表板>更新菜单处自动更新或访问https://wordpress.org/download/release-archive/
文件修订列表:
wp-admin / about.phpwp-admin / includes / class-wp-press-this.phpwp-admin / includes / class-wp-posts-list-table.phpwp-includes / version.phpwp-includes / class-wp-query.phpwp-includes / class-wp-comment.phpwp-includes / class-wp-term.phpwp-includes / rest-api / endpoints / class-wp-rest-comments-controller.phpwp-includes / rest-api / endpoints / class-wp-rest-taxonomies-controller.phpwp-includes / rest-api / endpoints / class-wp-rest-post-types-controller.phpwp-includes / rest-api / endpoints / class-wp-rest-posts-controller.phpwp-includes / rest-api / endpoints / class-wp-rest-terms-controller.phpwp-includes / rest-api / endpoints / class-wp-rest-post-statuses-controller.phpwp-includes / rest-api / endpoints / class-wp-rest-revisions-controller.phpwp-includes / rest-api / endpoints / class-wp-rest-users-controller.phpwp-includes / class-wp-post.phpwp-includes / rest-api.php