Version 5.2.4

On Oct. 14, 2019, WordPress 5.2.4 was released to the public.

Installation/Update Information

To download WordPress 5.2.4, update automatically from the Dashboard > Updates menu in your site’s admin area or visit https://wordpress.org/download/release-archive/.

For step-by-step instructions on installing and updating WordPress:

If you are new to WordPress, we recommend that you begin with the following:

Summary

From the WordPress 5.2.4 release post, WordPress versions 5.2 and earlier are affected by the following bugs, which are fixed in version 5.2.4. Updated versions of WordPress 5.1 and older releases since WordPress 3.7 are also available, for users who have not yet updated to 5.2.

  • Props to Evan Ricafort for finding an issue where stored XSS (cross-site scripting) could be added via the Customizer.
  • Props to J.D. Grimes who found and disclosed a method of viewing unauthenticated posts.
  • Props to Weston Ruter for finding a way to create a stored XSS to inject Javascript into style tags.
  • Props to David Newman for highlighting a method to poison the cache of JSON GET requests via the Vary: Origin header.
  • Props to Eugene Kolodenker who found a server-side request forgery in the way that URLs are validated.
  • Props to Ben Bidner of the WordPress Security Team who discovered issues related to referrer validation in the admin.

List of Files Revised

/wp-includes/class-wp.php
 /wp-includes/class-wp-query.php
 /wp-includes/functions.php
 /wp-includes/http.php
 /wp-includes/pluggable.php
 /wp-includes/rest-api.php 

First published

Last updated