Connect with us

Uncategorized

WordPress.org blog: WordPress 7.1.1 Maintenance and Security Release

Published

on

This security and maintenance release features 17 bug fixes on Core, 19 bug fixes for the Block Editor, and 11 security fixes.

Because this is a security release, it is recommended that you update your sites immediately.

You can download WordPress 7.1.1 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, the update process will begin automatically.

WordPress 7.1.1 is a short-cycle release. The next major release will be version 7.2 and is currently planned for December.

For more information, please visit the WordPress 7.1.1 HelpHub site.

Security updates included in this release

The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by Jakub Herman.
  • Comments, including notes, can be reparented by any authenticated user, reported by Justin Hart, Viridis Security.

Thank you to these WordPress contributors

This release was led by Adam Silverstein, Adrian Duffell, Andrei Draganescu, and Aaron Jorbin.

WordPress 7.1.1 would not have been possible without the contributions of the following people. Their asynchronous coordination to deliver maintenance and security fixes into a stable release is a testament to the power and capability of the WordPress community.

Aaron Jorbin, abrahamfariaz, Adam Silverstein, Adi Moldovan, Adrian Duffell, Aki Hamano, Alex Concha, Andrea Fercia, andreasca, Andrei Draganescu, Andrew Duthie, Andrew Serong, André Maneiro, annezazu, Anthony White, Arkaprabha Chowdhury, Ashar Fuadi, Azragh, Barry, buffer1024, Chunhui Ouyang, Courtney Robertson, Dagan, Daniel Richards, Daniel Rodriguez, Darshit Rajyaguru, David Biňovec, Deepak Kumar, Dennis Snell, DevSaiful, Dhruvang21, Dominik Schilling, Ehtisham Siddiqui, Ella Van Durpe, Erick Wambua, FahimMurshed, Fernando Tellado, fiocavallari, George Mamadashvili, George Vasiliades, gregbenz, Harish Tewari, Hit Bhalodia, Isabel Brison, Jake Spurlock, Jamie Dąbrowiecki, Jb Audras, Jeffrey Paul, Jeremy Felt, Jiwoon Kim, Joe Dolson, Joe Hoyle, Joe McGill, Joen Asmussen, Johannes Jülg, John Blackbourn, Jon Surrell, Jonathan Desrosiers, Josh, Kamran Abdul Aziz, Khokan Sardar, Kira Schroder, kleisauke, Kushagra Goyal, l1onofjudah, Lance Willett, luksusspokoju, Manzoor Wani, Marco Ciampini, marcs0h, Marin Atanasov, Michael, Mohammad Jangda, mrkenobi, Mukesh Panchal, Nawazkhan Pathan, Nik Tsekouras, Parth Jogi, Pascal Birchler, Paul Biron, Paul Kevan, Peter Wilson, Rafie Muhammad, ramonopoly, Rashed Hossain, Ressl, Riad Benguella, Rudy Faile, Sainath Poojary, Scott Kingsley Clark, Sergey Biryukov, Shail Mehta, Shameem – a11n, siliconforks, Slava Abakumov, Stephen Bernhardt, Sukhendu Sekhar Guria, Ugyen Dorji, Utsav Ladani, vortfu, Weston Ruter, w3bdsgn, wolf45 plus representatives from Automattic, Bluehost, GoDaddy, Pantheon, and WP Engine.

Backports

As a courtesy, the security fixes are being backported, where necessary, to all branches eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported. The backports are in progress and will ship as they become ready.

How to contribute

To get involved in WordPress core development, head over to Trac, pick a ticket, and join the conversation in the #core channel. Need help? Check out the Core Contributor Handbook.

Props to Ehtisham Siddiqui, Lance Willett, Weston Ruter, and Adam Silverstein for proofreading.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Uncategorized

How to Build a WooCommerce Print Shop Order Form With File Upload

Published

on

Build a WooCommerce print-shop page where customers upload artwork, pick a size, and unlock bulk discounts. Step-by-step PPOM walkthrough inside!

The post How to Build a WooCommerce Print Shop Order Form With File Upload appeared first on Themeisle Blog.

Continue Reading

Uncategorized

OpenStation Blog: A better way to use WordPress

Published

on

OpenStation Blog: A better way to use WordPress

I have been using WordPress for a long time, and I still love it. But wp-admin has basically worked in the same way for years.

OpenStation is our attempt to change that.

It’s a simple idea: instead of moving from one admin page to another, you have a desktop where you can open different parts of WordPress at the same time.

A screenshot of the OpenStation interface displaying a welcome message and a list of recent posts on the left, with a detailed view of the 'A better way to use WordPress' post on the right.

Your WordPress. Your workspace.

You can open your posts, pages, media, plugins, WooCommerce or any OpenStation app in different windows.

You can move them around, minimize them or put two things next to each other.

It may sound like a small difference, but once you start using WordPress this way, it changes a lot.

Real-time previews

You can also see your changes while you are working on them.

No need to constantly jump between wp-admin and the frontend just to check how something looks.

Screenshot of an OpenStation interface showcasing a blog post titled 'A better way to use WordPress' with a dark theme and multiple sections discussing features and mobile compatibility.

Apps inside WordPress

This is one of my favorite parts.

We are building apps like AllTerrain Forms, Photo Editor (And more!) specifically for OpenStation.

They are still WordPress plugins, but they feel much more like normal desktop apps.

A black Nike Air Force 1 sneaker displayed on a table, featuring a blue swoosh and 'OpenStation' branding.

WordPress on your phone

We also wanted OpenStation to work properly on mobile.

You can install it as a PWA and use WordPress from your phone almost like any other app.

A digital interface displaying a grid of application icons with sections for apps and system tools, including options for dashboard, posts, media, and settings.

Performance Is Fast. Really fast.

OpenStation is not only about changing how WordPress looks.

We have put a lot of work into making it fast. In many cases, opening and moving between WordPress screens is faster than using them directly from wp-admin.

We are also working on caching and preloading parts of WordPress before you need them.

The goal is very simple: you click something and it opens FAST.

And it is still WordPress

This is important.

We are not trying to replace WordPress or build another platform on top of it.

Your plugins are still your plugins. WooCommerce is still WooCommerce. Your content stays in WordPress.

OpenStation just gives you a different way to use all of it.

And, of course, it is open source.

Thank you

And finally, a big thank you to everyone in the WordPress community who has tried OpenStation, shared feedback, reported bugs or simply told others about it.

Grid of contributors to OpenStation showcasing their profile pictures and the number of merged pull requests (PRs) each has contributed.

And especially to all the contributors who are helping us build it. OpenStation would not be what it is today without you.

There is still a lot we want to do, and seeing people contributing, experimenting and building things with OpenStation is probably the best part of the whole project.

Thank you ❤

Continue Reading

Uncategorized

Open Channels FM: OCN Week in Review #4

Published

on

This week Robert Jacobi shared about the evolving landscape of open source and tech. Highlights include AI’s growing role in security, WordPress and Apache fortifying their processes, LibreOffice redefining productivity with privacy, LoopConf rethinking event funding, and Switzerland’s bold move toward digital sovereignty. Explore how accountability, control, and sustainability are shaping the future of open technology.

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.