Tuesday, March 11, 2025
HomeWordpressWordpress Update 4.9.7 - Critical Security Update to Resolve Bugs and Security...

WordPress Update 4.9.7 – Critical Security Update to Resolve Bugs and Security Issues

Published on

SIEM as a Service

Follow Us on Google News

WordPress Update 4.9.7 released covering fix for security issues and 17 bugs. All the WordPress version before 4.9.7 are affected arbitrary file deletion vulnerabilities.

Vulnerability Impact

The arbitrary file deletion vulnerability identified by RIPS Tech, by exploiting this vulnerability an attacker has the capability of deleting any fine from the WordPress installation.

If an attacker deletes core files like .htaccess, index.php files, and wp-config.php, it causes some serious issues, if you have no current backup is available.

Wordfence team detected second vulnerability that lies in the way wp_insert_post populates the metadata for the attachment.

Other Bug Fixes

Taxonomy: Improve cache handling for term queries. Posts, Post Types: Clear post password cookie when logging out.

Widgets: Allow basic HTML tags in sidebar descriptions on Widgets admin screen.
Community Events Dashboard: Always show the nearest WordCamp if one is coming up, even if there are multiple Meetups happening first.

Privacy: Make sure default privacy policy content does not cause a fatal error when flushing rewrite rules outside of the admin context.

WordPress published a blog post covering the full list of changes.

Mitigations

WordPress update 4.9.7 released with the security patches users are recommended to update their sites immediately.

WordPress Update 4.9.7

WordPress update (4.9.7) contains 17 maintenance fixes to the 4.9.7 release series. Updates are simple Dashboard >> Updates >> Update Now.

It is always a good idea to backup your WordPress before proceeding with the update, if there are any issues, you can restore your website.

Also Read

Penetration Testing with your WordPress Website-Detailed Explanation

Most Important Considerations Check to Setup Your WordPress Security

Dangerous WordPress Keylogger Returns via New Domains that Affected More than 1000 Websites

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

“Eleven11bot” Botnet Compromises 30,000 Webcams in Massive Attack

Cybersecurity experts have uncovered a massive Distributed Denial-of-Service (DDoS) botnet known as "Eleven11bot."This new...

SideWinder APT Deploys New Tools in Attacks on Military & Government Entities

The SideWinder Advanced Persistent Threat (APT) group has been observed intensifying its activities, particularly...

Apache Pinot Vulnerability Allows Attackers to Bypass Authentication

A significant security vulnerability affecting Apache Pinot, an open-source distributed data store designed for...

Lazarus Hackers Exploit 6 NPM Packages to Steal Login Credentials

North Korea's Lazarus Group has launched a new wave of attacks targeting the npm...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Over 10,000 WordPress Sites Exposed by Donation Plugin Code Execution Vulnerability

A critical security flaw in the widely used GiveWP – Donation Plugin and Fundraising Platform has...

WordPress Admins Warned of Fake Plugins Injecting Malicious Links into Websites

A new wave of cyberattacks targeting WordPress websites has been uncovered, with attackers leveraging...

Millions of WordPress Websites Vulnerable to Script Injection Due to Plugin Flaw

A critical security vulnerability in the Essential Addons for Elementor plugin, installed on over 2 million...