---
title: "WordPress Releases Security Update"
url: https://securityorb.com/wordpress-releases-security-update/
type: post
date: 2015-04-23
modified: 2015-04-23
markdown_url: https://securityorb.com/wordpress-releases-security-update.md
author: "Kellep Charles"
---

# WordPress Releases Security Update

## WordPress Releases Security Update

Original release date: April 23, 2015

WordPress 4.1.2 has been released to address multiple vulnerabilities, one of which could allow a site to be compromised by a remote attacker. WordPress 4.1.1 and earlier are affected by this vulnerability.

US-CERT recommends users and administrators review the [WordPress Security Release](https://wordpress.org/news/2015/04/wordpress-4-1-2/) and apply the necessary updates.

WordPress 4.1.2 is now available. This is a **critical security release** for all previous versions and we strongly encourage you to update your sites immediately.

WordPress versions 4.1.1 and earlier are affected by a critical cross-site scripting vulnerability, which could enable anonymous users to compromise a site. This was reported by [Cedric Van Bockhaven](https://cedricvb.be/) and fixed by [Gary Pendergast](http://pento.net/), [Mike Adams](http://blogwaffe.com/), and [Andrew Nacin](http://nacin.com/) of the WordPress security team.

We also fixed three other security issues:

 
- In WordPress 4.1 and higher, files with invalid or unsafe names could be uploaded. Discovered by [Michael Kapfer and Sebastian Kraemer of HSASec](http://hsasec.de/).
 
- In WordPress 3.9 and higher, a very limited cross-site scripting vulnerability could be used as part of a social engineering attack. Discovered by [Jakub Zoczek](http://zoczus.blogspot.com/).
 
- Some plugins were vulnerable to an SQL injection vulnerability. Discovered by Ben Bidner of the WordPress security team.

We also made four hardening changes, discovered by [J.D. Grimes](http://codesymphony.co/), Divyesh Prajapati, [Allan Collins](http://www.allancollins.net/), [Marc-Alexandre Montpas](https://sucuri.net/) and [Jeff Bowen](https://profiles.wordpress.org/jblz).

We appreciated the [responsible disclosure](https://make.wordpress.org/core/handbook/reporting-security-vulnerabilities/) of these issues directly to our security team. For more information, see the [release notes](https://codex.wordpress.org/Version_4.1.2) or consult the [list of changes](https://core.trac.wordpress.org/log/branches/4.1?rev=32234&stop_rev=32144).

[Download WordPress 4.1.2](https://wordpress.org/download/) or venture over to **Dashboard → Updates** and simply click “Update Now.” Sites that support automatic background updates are already beginning to update to WordPress 4.1.2.

Thanks to everyone who contributed to 4.1.2: [Allan Collins](https://profiles.wordpress.org/collinsinternet), [Alex Concha](https://profiles.wordpress.org/xknown), [Andrew Nacin](https://profiles.wordpress.org/nacin), [Andrew Ozz](https://profiles.wordpress.org/azaozz), [Ben Bidner](https://profiles.wordpress.org/vortfu), [Boone Gorges](https://profiles.wordpress.org/boonbgorges), [Dion Hulse](https://profiles.wordpress.org/dd32), [Dominik Schilling](https://profiles.wordpress.org/ocean90), [Drew Jaynes](https://profiles.wordpress.org/DrewAPicture), [Gary Pendergast](https://profiles.wordpress.org/pento), [Helen Hou-Sandí](https://profiles.wordpress.org/helen), [John Blackbourn](https://profiles.wordpress.org/johnbillion), and [Mike Adams](https://profiles.wordpress.org/mdawaffe).

A number of plugins also released security fixes yesterday. Keep everything updated to stay secure. If you’re a plugin author, please read [this post](https://make.wordpress.org/plugins/2015/04/20/fixing-add_query_arg-and-remove_query_arg-usage/) to confirm that your plugin is not affected by the same issue. Thank you to all of the plugin authors who worked closely with our security team to ensure a coordinated response.

*Already testing WordPress 4.2? The third release candidate is now available ([zip](https://wordpress.org/wordpress-4.2-RC3.zip)) and it contains these fixes. For more on 4.2, see [the RC 1 announcement post](https://wordpress.org/news/2015/04/wordpress-4-2-release-candidate/).*
