WordPress 3.9.2 Security Release Out, Immediate Update Recommended

SMS Text

WordPress 3.9.2 has just been rolled out as a security release for all previous versions. WordPress strongly recommends that you update your sites immediately.

This release fixes a possible denial of service issue in PHP’s XML processing, reported by Nir Goldshlager of the Salesforce.com Product Security Team. It was fixed by Michael Adams and Andrew Nacin of the WordPress security team and David Rothstein of the Drupal security team. This is the first time our two projects have coordinated joint security releases.

Other security changes in WordPress 3.9.2 include:

  • Fixes a possible but unlikely code execution when processing widgets (WordPress is not affected by default).
  • Prevents information disclosure via XML entity attacks in the external GetID3 library.
  • Adds protections against brute attacks against CSRF tokens.
  • Contains some additional security hardening, like preventing cross-site scripting that could be triggered only by administrators.

Sites that support automatic background updates will be updated to WordPress 3.9.2 within 12 hours. To get this latest security update manually, point your browser to Dashboard → Updates and simply click “Update Now”.

For more information, here is a full set of release notes.

Matt Southern

Matt Southern

Lead News Writer
Matt Southern is the lead news writer at Search Engine Journal. His passion for helping people in all aspects of online marketing flows through in the expert industry coverage he provides.
Matt Southern
Get the latest news from Search Engine Journal!
We value your privacy! See our policy here.
  • Parnable

    My sites are always updating autonatically. It`s a long time when I begin to realize that WordPress is aiming to expand the boundary of implementation from simple blog to full-finctional media-portal. Customizable theme-size, menu, a lot of new features, taxonomies, optimization for a big load and now security. Well done, WP, that`s the way to go 🙂

    • http://www.the-sophia-hills.com.sg Sophia Hills

      Sorry, is there a setting to update automatically? Could you point me to that as its pretty taxing to update all my sites individually every now and then.. thanks in advance

  • http://alrenpages.com Alberto Rendon

    Thanks for this info… recently my host domain reminded me many time of this security… but I ignored it because I thought it is not very important. And beside, I don’t know how to it in my control panel… So now I will do it in my dashboard. Thanks!