WordPress 4.7.1 with 8 security updates and 61 fixes

The 4.7.1 version of WordPress CMS has been released with 8 security updates and fixes for 61 bugs of the previous version.

Below are the security snapshots fixed in the new WordPress update:wordpress

Remote Code Execution (RCE) in PHPMailer
The REST API exposed data for all users who had written a post. WrrdPress 4.7.1 limits it to types of posts that we define that should appear.
Cross-site scripting (XSS) through the plugin name or version header of update-core.php.
Cross-site request forgery (CSRF) bypass through a Flash file.
Cross-site scripting (XSS) via theme name fallback.
Check for whether the default mail.example.com setting has been changed in the option that allows posts by email.
A cross-site request forgery (CSRF) discovered in widget editing.
Small encryption security on multisite activation key.

You can read the bug fixes from the link below.


