Version 4.0.11

On 6 May, 2016, WordPress 4.0.11 was released to the public.

Installation/Update Information

To download WordPress 4.0.11, update automatically from the Dashboard > Updates menu in your site’s admin area or visit https://wordpress.org/download/release-archive/.

For step-by-step instructions on installing and updating WordPress:

If you are new to WordPress, we recommend that you begin with the following:

Summary

From the WordPress 4.5.2 release notes, WordPress versions 4.5.1 and earlier are affected by a SOME vulnerability through Plupload, the third-party library WordPress uses for uploading files. WordPress versions 4.2 through 4.5.1 are vulnerable to reflected XSS using specially crafted URIs through MediaElement.js, the third-party library used for media players. MediaElement.js and Plupload have also released updates fixing these issues.

Both issues were analyzed and reported by Mario Heiderich, Masato Kinugawa, and Filedescriptor from Cure53. Thanks to the team for practicing responsible disclosure, and to the Plupload and MediaElement.js teams for working closely with us to coördinate and fix these issues.

List of Files Revised

/wp-includes/http.php
/wp-includes/class-snoopy.php
/wp-includes/taxonomy.php
/wp-includes/version.php
/wp-includes/js/plupload/plupload.flash.swf
/readme.html
/wp-admin/network/settings.php
/wp-admin/user-edit.php
/wp-admin/about.php

First published

Last updated