WordPress 4.2.2 is now available


WordPress 4.2.2 has been released and available for download or update in your WordPress dashboard. This is the second maintenance release of 4.2 ("Powell"), addressed a critical cross-site scripting vulnerabilities, which could enable anonymous users to compromise a site.

Download WordPress
WordPress 4.2.2 is available for download or update in WordPress dashboard. Sites that support automatic background updates will be updated to WordPress 4.2.2 . For a full description of the system requirements, and the download links, see: Download WordPress 4.2.2

Overview
WordPress is an open source CMS, often used as a blog publishing application powered by PHP and MySQL. It has many features including a plugin architecture and a templating system. Used by over 300 of the 10,000 biggest websites, WordPress is the most popular blog software in use today.

It was first released in May 2003 by Matt Mullenweg as a fork of b2/cafelog. As of September 2009, it was being used by 202 million websites worldwide.

WordPress 4.2 "Powell" includes a number of new features that help you communicate and share, globally. More details can be found here.

What's new in WordPress 4.2.2
Version 4.2.2 addresses two security issues:
  • The Genericons icon font package, which is used in a number of popular themes and plugins, contained an HTML file vulnerable to a cross-site scripting attack. All affected themes and plugins hosted on WordPress.org (including the Twenty Fifteen default theme) have been updated today by the WordPress security team to address this issue by removing this nonessential file. To help protect other Genericons usage, WordPress 4.2.2 proactively scans the wp-content directory for this HTML file and removes it.
  • WordPress versions 4.2 and earlier are affected by a critical cross-site scripting vulnerability, which could enable anonymous users to compromise a site.

The release also includes hardening for a potential cross-site scripting vulnerability when using the visual editor. The full details of changes that are in WordPress 4.2.2 is available in the changelog.

Source:
WordPress News

No comments: