The recent WordPress including the WordPress 4.9.1 updates have seen more emphasis given to security than for a long time. This comes from a renewed commitment by the team towards hardening security. In their blog, WordPress mentioned that the WordPress 4.9.1 update fixes four security issues that affected WordPress versions 4.9 and earlier.
i. Using properly generated hash key for newbloguser: Using a properly generated hash key means it harder to hackers to add new users to your WordPress database and use that account to take your WordPress website.
ii. Adding escape to language attributes in the HTML elements: In certain cases where the language attributes have unsecured strings in them, they are now filtered and also the quotes are escaped correctly.
iii. Escaping Attributes of Enclosures in RSS and Atom Feeds: Enclosures are used by RSS and Atom Feeds as a means of attaching multimedia files to your feed. These enclosure tags use attributes which were previously insecure. With WordPress 4.9.1, they are properly escaped.
iv. Prevent users without unfiltered_html capability from uploading Javascript files: This is another great improved in preventing script attacks by unauthorized users. Uploading Javascript files is a cunning way of attacking a WordPress website and that has been resolved now.
Apart from these four security fixes, there were eleven other fixes:
JS errors caused when using certain languages:
Due to MediaElement upgrade, there has been JS errors caused when certain laguages are being used. A memeber of the WordPress Core Development team shares that it affects javascript heavy pages like the customizer page and the widgets page.
As you can see that a few of those issues are caused by the WordPress 4.9 update and might not have affected anything long term. The major security fixes, however, are fixes for pre-WordPress 4.9.1 versions and hence it is strongly adviced that you update your WordPress website now.
Digital detox is a process in which a person stops using tech products such as…
How to make a webcomic website? Don't know the first thing about it? Here's how…
Over 600 websites are created every minute, that’s over 200,000 every day and 73 million…
WordPress recently announced the release of WordPress 4.8.3 with an important security fix. It is…
Glad to announce that we have released Helpie 1.2.3 with some amazing new features. Take…
We have just released version 1.1 of our WordPress Knowledge Base plugin, Helpie WP. See…