Friday, January 31, 2025
HomeWordpressWordpress Update 4.9.7 - Critical Security Update to Resolve Bugs and Security...

WordPress Update 4.9.7 – Critical Security Update to Resolve Bugs and Security Issues

Published on

SIEM as a Service

Follow Us on Google News

WordPress Update 4.9.7 released covering fix for security issues and 17 bugs. All the WordPress version before 4.9.7 are affected arbitrary file deletion vulnerabilities.

Vulnerability Impact

The arbitrary file deletion vulnerability identified by RIPS Tech, by exploiting this vulnerability an attacker has the capability of deleting any fine from the WordPress installation.

If an attacker deletes core files like .htaccess, index.php files, and wp-config.php, it causes some serious issues, if you have no current backup is available.

Wordfence team detected second vulnerability that lies in the way wp_insert_post populates the metadata for the attachment.

Other Bug Fixes

Taxonomy: Improve cache handling for term queries. Posts, Post Types: Clear post password cookie when logging out.

Widgets: Allow basic HTML tags in sidebar descriptions on Widgets admin screen.
Community Events Dashboard: Always show the nearest WordCamp if one is coming up, even if there are multiple Meetups happening first.

Privacy: Make sure default privacy policy content does not cause a fatal error when flushing rewrite rules outside of the admin context.

WordPress published a blog post covering the full list of changes.

Mitigations

WordPress update 4.9.7 released with the security patches users are recommended to update their sites immediately.

WordPress Update 4.9.7

WordPress update (4.9.7) contains 17 maintenance fixes to the 4.9.7 release series. Updates are simple Dashboard >> Updates >> Update Now.

It is always a good idea to backup your WordPress before proceeding with the update, if there are any issues, you can restore your website.

Also Read

Penetration Testing with your WordPress Website-Detailed Explanation

Most Important Considerations Check to Setup Your WordPress Security

Dangerous WordPress Keylogger Returns via New Domains that Affected More than 1000 Websites

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hackers Exploiting DNS Poisoning to Compromise Active Directory Environments

A groundbreaking technique for Kerberos relaying over HTTP, leveraging multicast poisoning, has been recently...

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria...

500 Million Proton VPN & Pass Users at Risk Due to Memory Protection Vulnerability

Proton, the globally recognized provider of privacy-focused services such as Proton VPN and Proton...

Arcus Media Ransomware Strikes: Files Locked, Backups Erased, and Remote Access Disabled

The cybersecurity landscape faces increasing challenges as Arcus Media ransomware emerges as a highly...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

10,000 WordPress Websites Hacked to Distributing MacOS and Microsoft Malware

Over 10,000 WordPress websites have been hijacked to deliver malicious software targeting both macOS...

WordPress Plugin Vulnerability Exposes 23k+ Websites to Hacking

Researchers from Patchstack have warned that over 23,000 real estate websites using the popular...

Credit Card Skimmer Hits WordPress Checkout Pages, Stealing Payment Data

Researchers analyzed a new stealthy credit card skimmer that targets WordPress checkout pages by...