WordPress 5.7.1 is now accessible!
This safety and upkeep launch options 26 bug fixes along with two safety fixes. As a result of this can be a safety launch, it’s endorsed that you just replace your websites instantly. All variations since WordPress 4.7 have additionally been up to date.
WordPress 5.7.1 is a short-cycle safety and upkeep launch. The subsequent main launch shall be model 5.8.
You’ll be able to obtain WordPress 5.7.1 by downloading from WordPress.org, or go to your Dashboard → Updates and click on Replace Now.
When you have websites that help automated background updates, they’ve already began the replace course of.
Two safety points have an effect on WordPress variations between 4.7 and 5.7. For those who haven’t but up to date to five.7, all WordPress variations since 4.7 have additionally been up to date to repair the next safety points:
- Thanks SonarSource for reporting an XXE vulnerability throughout the media library affecting PHP 8.
- Thanks Mikael Korpela for reporting a knowledge publicity vulnerability throughout the REST API.
Thanks to all the reporters for privately disclosing the vulnerabilities. This gave the safety workforce time to repair the vulnerabilities earlier than WordPress websites may very well be attacked.
Props to Adam Zielinski, Pascal Birchler, Peter Wilson, Juliette Reinders Folmer, Alex Concha, Ehtisham Siddiqui, Timothy Jacobs and the WordPress safety workforce for his or her work on these points.
Thanks and props!
Along with the safety researchers and launch squad members talked about above, thanks to everybody who helped make WordPress 5.7.1 occur:
99w, Adam Silverstein, Andrew Ozz, annalamprou, anotherdave, Ari Stathopoulos, Ayesh Karunaratne, bobbingwide, Brecht, Daniel Richards, David Baumwald, dkoo, Dominik Schilling, dragongate, eatsleepcode, Ella van Durpe, Erik, Fabian Pimminger, Felix Arntz, Florian TIAR, gab81, Gal Baras, Geoffrey, George Mamadashvili, Glen Davies, Greg Ziółkowski, grzim, Ipstenu (Mika Epstein), Jake Spurlock, Jayman Pandya, Jb Audras, Joen A., Johan Jonk Stenström, Johannes Kinast, John Blackbourn, John James Jacoby, Jonathan Desrosiers, Josee Wouters, Joy, k3nsai, Kelly Choyce-Dwan, Kerry Liu, Marius L. J., Mel Choyce-Dwan, Mikhail Kobzarev, mmuyskens, Mukesh Panchal, nicegamer7, Otshelnik-Fm, Paal Joachim Romdahl, palmiak, Pascal Birchler, Peter Wilson, pwallner, Rachel Baker, Riad Benguella, Rinat Khaziev, Robert Anderson, Roger Theriault, Sergey Biryukov, Sergey Yakimov, SirStuey, stefanjoebstl, Stephen Bernhardt, Sumit Singh, Sybre Waaijer, Synchro, Terri Ann, tigertech, Timothy Jacobs, tmatsuur, TobiasBg, Tonya Mork, Toru Miki, Ulrich, and Vlad T.