WordPress Update 4.9.7 released covering fix for security issues and 17 bugs. All the WordPress version before 4.9.7 are affected arbitrary file deletion vulnerabilities.
The arbitrary file deletion vulnerability identified by RIPS Tech, by exploiting this vulnerability an attacker has the capability of deleting any fine from the WordPress installation.
If an attacker deletes core files like .htaccess, index.php files, and wp-config.php, it causes some serious issues, if you have no current backup is available.
Wordfence team detected second vulnerability that lies in the way wp_insert_post populates the metadata for the attachment.
Taxonomy: Improve cache handling for term queries. Posts, Post Types: Clear post password cookie when logging out.
Widgets: Allow basic HTML tags in sidebar descriptions on Widgets admin screen.
Community Events Dashboard: Always show the nearest WordCamp if one is coming up, even if there are multiple Meetups happening first.
Privacy: Make sure default privacy policy content does not cause a fatal error when flushing rewrite rules outside of the admin context.
WordPress published a blog post covering the full list of changes.
WordPress update 4.9.7 released with the security patches users are recommended to update their sites immediately.
WordPress update (4.9.7) contains 17 maintenance fixes to the 4.9.7 release series. Updates are simple Dashboard >> Updates >> Update Now.
It is always a good idea to backup your WordPress before proceeding with the update, if there are any issues, you can restore your website.
Penetration Testing with your WordPress Website-Detailed Explanation
Most Important Considerations Check to Setup Your WordPress Security
Dangerous WordPress Keylogger Returns via New Domains that Affected More than 1000 Websites
A new project has exposed a critical attack vector that exploits protocol vulnerabilities to disrupt…
A threat actor known as #LongNight has reportedly put up for sale remote code execution…
Ivanti disclosed two critical vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager Mobile…
Hackers are increasingly targeting macOS users with malicious clones of Ledger Live, the popular application…
The European Union has escalated its response to Russia’s ongoing campaign of hybrid threats, announcing…
Venice.ai has rapidly emerged as a disruptive force in the AI landscape, positioning itself as…