WordPress 3.6.1
11 September 2013
WordPress version 3.6.1 is now available (security release).
Upgrading to WordPress 3.6.1
WordPress 3.6.1 can be upgraded to (or installed) using any of Installatron's products. Use Installatron's optional Automatic Update feature to automatically apply WordPress updates as new versions are released, or use Installatron's Clone feature to duplicate an existing WordPress install to test the 3.6.1 upgrade prior to applying it live. Get started managing your WordPress installations with Installatron
What's New in WordPress 3.6.1
This maintenance release addresses 13 bugs with version 3.6.
Three security issues:
- Remote Code Execution: Block unsafe PHP de-serialization that could occur in limited situations and setups, which can lead to remote code execution. Reported by Tom Van Goethem. CVE pending.
- Privilege Escalation: Prevent a user with an Author role, using a specially crafted request, from being able to create a post "written by" another user. Reported by Anakorn Kyavatanakij. CVE pending.
- Link Injection / Open Redirect: Fix insufficient input validation that could result in redirecting or leading a user to another website. Reported by Dave Cummo, a Northrup Grumman subcontractor for the U.S. Centers for Disease Control and Prevention. CVE pending.
Additional security hardening:
- Updated security restrictions around file uploads to mitigate the potential for cross-site scripting. The extensions .swf and .exe are no longer allowed by default, and .htm and .html are only allowed if the user has the ability to use unfiltered HTML.
Installatron:
- Install, Update, and Edit: All languages updated for version 3.6.1.