WordPress 3.6.1

WordPress 3.6.1 has been release. This is a maintenance and security release, so please upgrade as soon as you get the chance.

This .1 release fixes 13 bugs and the below security issues:

  • Block unsafe PHP unserialization that could occur in limited situations and setups, which can lead to remote code execution. Reported by Tom Van Goethem.
  • Prevent a user with an Author role, using a specially crafted request, from being able to create a post “written by” another user. Reported by Anakorn Kyavatanakij.
  • Fix insufficient input validation that could result in redirecting or leading a user to another website. Reported by Dave Cummo, a Northrup Grumman subcontractor for the U.S. Centers for Disease Control and Prevention.
  • Additionally, we’ve adjusted security restrictions around file uploads to mitigate the potential for cross-site scripting.

Download: WordPress 3.6.1

1 Star2 Stars3 Stars4 Stars5 Stars (43 votes, average: 4.05 out of 5)