Skip to main content

WordPress releases important security patch, version 4.0.1

wordpress-logoWordPress has just released version 4.0.1, which is a small update that helps to resolve some potentially nasty security holes and everyone is encouraged to update their sites immediately.

Among the fixes:

  • Three cross-site scripting issues that a contributor or author could use to compromise a site.
  • A cross-site request forgery that could be used to trick a user into changing their password.
  • An issue that could lead to a denial of service when passwords are checked.
  • Additional protections for server-side request forgery attacks when WordPress makes HTTP requests.
  • An extremely unlikely hash collision could allow a user’s account to be compromised, that also required that they haven’t logged in since 2008.
  • WordPress now invalidates the links in a password reset email if the user remembers their password, logs in, and changes their email address.

If you’re already on version 4.0, the update should happen automatically. If you have GreenMellen monitoring your sites, we’ll verify that the update occurred as it should (or update manually) and that things are running smoothly.

If you’re on an older version or with a host that doesn’t support automatic WordPress updates, you’ll want to go in and update yours manually (after you back it up!) as soon as possible.

You can read more about this on the official WordPress blog.

About the Author

Mickey Mellen

Co-Founder and Technical Director

View Mickey's Profile

More from Our Blog

5 Most Common Marketing Challenges Small Business Owners Face

Marketing is deceptively complex. Creating a Facebook page and building a basic website seems simple, but having an online presence doesn’t automatically make you effective…

Read More
mad formal executive man yelling at camera

Growing Your Website Content Sustainably Over The Long Run

There are over one billion websites in the world today—All of which are competing for attention and new customers, all while trying to improve their…

Read More

H1 & H2: Why You Should Always Use Headers in Your Website Content

Not only do headers make online content easier for humans to understand, but header tags (like H1 and H2) also guide bots on how to...

Read More
white printer paper on white table