WordPress.org

Codex

Attention Interested in functions, hooks, classes, or methods? Check out the new WordPress Code Reference!

Version 3.9.6

On May 6, 2015, WordPress 3.9.6 was released to the public, along with WordPress 4.2.2. This is both a security update for all previous WordPress versions, and a maintenance release for versions 4.1 and newer.

Installation/Update Information

To download WordPress 3.9.6, update automatically from the Dashboard > Updates menu in your site's admin area or visit https://wordpress.org/download/release-archive/.

For step-by-step instructions on installing and updating WordPress:

If you are new to WordPress, we recommend that you begin with the following:

Summary

From the announcement post, WordPress 3.9.6 fixes a cross-site scripting vulnerability contained in an HTML file shipped with recent Genericons packages included in the Twenty Fifteen theme as well as a number of popular plugins by removing the file. Auto-updates and manual updates will remove this file, however manual installations and those using VCS checkout (like SVN) will not remove this file. Version 3.9.6 also improves on a fix for a critical cross-site scripting vulnerability introduced in 3.9.5.

The release also includes hardening for a potential cross-site scripting vulnerability when using the Visual editor.

WordPress 3.9.6 also contains fixes for 3 bugs from 3.9.5, including:

  • Lowers memory usage for a regex checking for UTF-8 encoding
  • Fixes how WordPress checks for encoding when sending strings to MySQL

List of Files Revised

wp-admin/about.php
wp-admin/includes/upgrade.php
wp-admin/includes/update-core.php
wp-includes/wp-db.php
wp-includes/version.php
wp-includes/compat.php
wp-includes/js/tinymce/plugins/wordpress/plugin.js
readme.html
See also: other WordPress Versions.