Tuesday, April 15, 2025
HomeWordpressWordpress Update 4.9.7 - Critical Security Update to Resolve Bugs and Security...

WordPress Update 4.9.7 – Critical Security Update to Resolve Bugs and Security Issues

Published on

SIEM as a Service

Follow Us on Google News

WordPress Update 4.9.7 released covering fix for security issues and 17 bugs. All the WordPress version before 4.9.7 are affected arbitrary file deletion vulnerabilities.

Vulnerability Impact

The arbitrary file deletion vulnerability identified by RIPS Tech, by exploiting this vulnerability an attacker has the capability of deleting any fine from the WordPress installation.

If an attacker deletes core files like .htaccess, index.php files, and wp-config.php, it causes some serious issues, if you have no current backup is available.

- Advertisement - Google News

Wordfence team detected second vulnerability that lies in the way wp_insert_post populates the metadata for the attachment.

Other Bug Fixes

Taxonomy: Improve cache handling for term queries. Posts, Post Types: Clear post password cookie when logging out.

Widgets: Allow basic HTML tags in sidebar descriptions on Widgets admin screen.
Community Events Dashboard: Always show the nearest WordCamp if one is coming up, even if there are multiple Meetups happening first.

Privacy: Make sure default privacy policy content does not cause a fatal error when flushing rewrite rules outside of the admin context.

WordPress published a blog post covering the full list of changes.

Mitigations

WordPress update 4.9.7 released with the security patches users are recommended to update their sites immediately.

WordPress Update 4.9.7

WordPress update (4.9.7) contains 17 maintenance fixes to the 4.9.7 release series. Updates are simple Dashboard >> Updates >> Update Now.

It is always a good idea to backup your WordPress before proceeding with the update, if there are any issues, you can restore your website.

Also Read

Penetration Testing with your WordPress Website-Detailed Explanation

Most Important Considerations Check to Setup Your WordPress Security

Dangerous WordPress Keylogger Returns via New Domains that Affected More than 1000 Websites

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Cloud Misconfigurations – A Leading Cause of Data Breaches

Cloud computing has transformed the way organizations operate, offering unprecedented scalability, flexibility, and cost...

Security Awareness Metrics That Matter to the CISO

Security awareness has become a critical component of organizational defense strategies, particularly as companies...

New ‘Waiting Thread Hijacking’ Malware Technique Evades Modern Security Measures

Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking"...

From ISO to NIS2 – Mapping Compliance Requirements Globally

The global regulatory landscape for cybersecurity is undergoing a seismic shift, with the European...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Over 100,000 WordPress Plugin Vulnerability Exploited Just 4 Hours After Disclosure

Over 100,000 WordPress websites have been exposed to a critical security vulnerability, following the...

Rogue Account‑Creation Flaw Leaves 100 K WordPress Sites Exposed

A severe vulnerability has been uncovered in the SureTriggers WordPress plugin, which could leave...

50,000+ WordPress Sites Vulnerable to Privilege Escalation Attacks

In a recent cybersecurity development, over 50,000 WordPress websites using the Uncanny Automator plugin...