Categories: Wordpress

WordPress Update 4.9.7 – Critical Security Update to Resolve Bugs and Security Issues

WordPress Update 4.9.7 released covering fix for security issues and 17 bugs. All the WordPress version before 4.9.7 are affected arbitrary file deletion vulnerabilities.

Vulnerability Impact

The arbitrary file deletion vulnerability identified by RIPS Tech, by exploiting this vulnerability an attacker has the capability of deleting any fine from the WordPress installation.

If an attacker deletes core files like .htaccess, index.php files, and wp-config.php, it causes some serious issues, if you have no current backup is available.

Wordfence team detected second vulnerability that lies in the way wp_insert_post populates the metadata for the attachment.

Other Bug Fixes

Taxonomy: Improve cache handling for term queries. Posts, Post Types: Clear post password cookie when logging out.

Widgets: Allow basic HTML tags in sidebar descriptions on Widgets admin screen.
Community Events Dashboard: Always show the nearest WordCamp if one is coming up, even if there are multiple Meetups happening first.

Privacy: Make sure default privacy policy content does not cause a fatal error when flushing rewrite rules outside of the admin context.

WordPress published a blog post covering the full list of changes.

Mitigations

WordPress update 4.9.7 released with the security patches users are recommended to update their sites immediately.

WordPress Update 4.9.7

WordPress update (4.9.7) contains 17 maintenance fixes to the 4.9.7 release series. Updates are simple Dashboard >> Updates >> Update Now.

It is always a good idea to backup your WordPress before proceeding with the update, if there are any issues, you can restore your website.

Also Read

Penetration Testing with your WordPress Website-Detailed Explanation

Most Important Considerations Check to Setup Your WordPress Security

Dangerous WordPress Keylogger Returns via New Domains that Affected More than 1000 Websites

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Lumma Stealer Attacking Users To Steal Login Credentials From Browsers

Researchers observed Lumma Stealer activity across multiple online samples, including PowerShell scripts and a disguised…

2 days ago

New ‘OtterCookie’ Malware Attacking Software Developers Via Fake Job Offers

Palo Alto Networks reported the Contagious Interview campaign in November 2023, a financially motivated attack…

2 days ago

NjRat 2.3D Pro Edition Shared on GitHub: A Growing Cybersecurity Concern

The recent discovery of the NjRat 2.3D Professional Edition on GitHub has raised alarms in…

2 days ago

Palo Alto Networks Vulnerability Puts Firewalls at Risk of DoS Attacks

A critical vulnerability, CVE-2024-3393, has been identified in the DNS Security feature of Palo Alto…

2 days ago

Araneida Scanner – Hackers Using Cracked Version Of Acunetix Vulnerability Scanner

Threat Analysts have reported alarming findings about the "Araneida Scanner," a malicious tool allegedly based…

3 days ago

A Dark Web Operation Acquiring KYC Details TO Bypass Identity Verification Systems

A major dark web operation dedicated to circumventing KYC (Know Your Customer) procedures, which involves…

3 days ago