File: /home/regevl/Maildir/new/1588229526.H308992P25729.server.ded1-sh.uk.proginter.com
Return-path: <SRS0=89x6eo=6O=proginter.com=customer@tll-hospitality.co.il>
Envelope-to: regevl@tll-hospitality.co.il
Delivery-date: Thu, 30 Apr 2020 09:52:06 +0300
Received: from root by server.ded1-sh.uk.proginter.com with local (Exim 4.92.3)
(envelope-from <customer@proginter.com>)
id 1jU33G-0006ft-9K
for regevl@tll-hospitality.co.il; Thu, 30 Apr 2020 09:52:06 +0300
To: regevl@tll-hospitality.co.il
Subject: [ProgInter Applications] WordPress 5.4.1 now available (security release)
Date: Thu, 30 Apr 2020 07:52:06 +0100
From: customer@proginter.com
Message-ID: <d5d0279b00c7ba91aa7707a249429a15@server.ded1-sh.uk.proginter.com>
X-Mailer: Installatron Plugin 9.1.51
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
This is an automated email from ProgInter Applications. To unsubscribe from these emails or to change notification settings, login to your web hosting control panel, navigate to the ProgInter Applications tool, and select the installed applications you wish to modify.
An update to WordPress 5.4.1 (security release) is now available for the WordPress installations you are managing using ProgInter Applications. The following can be updated:
- http://thespa.to-web.co.il
The changes for this version are:
Security
* Props to Muaz Bin Abdus Sattar and Jannes who both independently reported an issue where password reset tokens were not properly invalidated
* Props to ka1n4t for finding an issue where certain private posts can be viewed unauthenticated
* Props to Evan Ricafort for discovering an XSS issue in the Customizer
* Props to Ben Bidner from the WordPress Security Team who discovered an XSS issue in the search block
* Props to Nick Daugherty from WordPress VIP / WordPress Security Team who discovered an XSS issue in wp-object-cache
* Props to Ronnie Goodrich (Kahoots) and Jason Medeiros who independently reported an XSS issue in file uploads.
* Props to Weston Ruter for fixing a stored XSS vulnerability in the WordPress customizer.
* Additionally, an authenticated XSS issue in the block editor was discovered by Nguyen the Duc in WordPress 5.4 RC1 and RC2. It was fixed in 5.4 RC5. We wanted to be sure to give credit and thank them for all of their work in making WordPress more secure.
Login to your web hosting control panel and navigate to the ProgInter Applications tool to update your installed applications.
End of report.