wordpress-featured-image-760x350
WordPress

WordPress 3.9.2 Security Release Out, Immediate Update Recommended

WordPress 3.9.2 has just been rolled out as a security release for all previous versions. WordPress strongly recommends that you update your sites immediately.

This release fixes a possible denial of service issue in PHP’s XML processing, reported by Nir Goldshlager of the Salesforce.com Product Security Team. It was fixed by Michael Adams and Andrew Nacin of the WordPress security team and David Rothstein of the Drupal security team. This is the first time our two projects have coordinated joint security releases.

Other security changes in WordPress 3.9.2 include:

  • Fixes a possible but unlikely code execution when processing widgets (WordPress is not affected by default).
  • Prevents information disclosure via XML entity attacks in the external GetID3 library.
  • Adds protections against brute attacks against CSRF tokens.
  • Contains some additional security hardening, like preventing cross-site scripting that could be triggered only by administrators.

Sites that support automatic background updates will be updated to WordPress 3.9.2 within 12 hours. To get this latest security update manually, point your browser to Dashboard → Updates and simply click “Update Now”.

For more information, here is a full set of release notes.

 WordPress 3.9.2 Security Release Out, Immediate Update Recommended

Matt Southern

Freelance Writer at MattSouthern.com
Matt Southern is the lead news writer at Search Engine Journal. His passion for helping people in all aspects of online marketing flows through in the expert articles he contributes to many well respected publications across the web. Contact him via his website if you'd like him to write for you.
 WordPress 3.9.2 Security Release Out, Immediate Update Recommended

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

3 thoughts on “WordPress 3.9.2 Security Release Out, Immediate Update Recommended

  1. My sites are always updating autonatically. It`s a long time when I begin to realize that WordPress is aiming to expand the boundary of implementation from simple blog to full-finctional media-portal. Customizable theme-size, menu, a lot of new features, taxonomies, optimization for a big load and now security. Well done, WP, that`s the way to go :)

    1. Sorry, is there a setting to update automatically? Could you point me to that as its pretty taxing to update all my sites individually every now and then.. thanks in advance

  2. Thanks for this info… recently my host domain reminded me many time of this security… but I ignored it because I thought it is not very important. And beside, I don’t know how to it in my control panel… So now I will do it in my dashboard. Thanks!