File: /home/wynnelaw5142/mail/new/1438723514.H734664P3204.p3plcpnl0292.prod.phx3.secureserver.net,S=2588
Return-path: <noreply@p3plcpnl0292.prod.phx3.secureserver.net>
Envelope-to: wynnelaw5142@p3plcpnl0292.prod.phx3.secureserver.net
Delivery-date: Tue, 04 Aug 2015 14:25:14 -0700
Received: from root by p3plcpnl0292.prod.phx3.secureserver.net with local (Exim 4.85)
(envelope-from <noreply@p3plcpnl0292.prod.phx3.secureserver.net>)
id 1ZMjhy-0000ou-LN
for wynnelaw5142@p3plcpnl0292.prod.phx3.secureserver.net; Tue, 04 Aug 2015 14:25:14 -0700
To: wynnelaw5142@p3plcpnl0292.prod.phx3.secureserver.net
Subject: [Installatron] WordPress 4.2.4 now available (security release)
Date: Tue, 4 Aug 2015 23:25:14 +0200
From: noreply@p3plcpnl0292.prod.phx3.secureserver.net
Message-ID: <b2afb2412f302e96ebd7945b0ab0a497@p3plcpnl0292.prod.phx3.secureserver.net>
X-Priority: 3
X-Mailer: Installatron Plugin 9.1.17
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This is an automated email from Installatron. To unsubscribe from these emails or to change notification settings, login to your web hosting control panel, navigate to the Installatron tool, and select the installed applications you wish to modify.
An update to WordPress 4.2.4 (security release) is now available for the WordPress installations you are managing using Installatron. The following can be updated:
- http://www.wynnelawfirm.com
The changes for this version are:
This is a security release for all previous versions and we strongly encourage you to update your sites immediately.
This release addresses six issues, including three cross-site scripting vulnerabilities and a potential SQL injection that could be used to compromise a site, which were discovered by Marc-Alexandre Montpas of Sucuri, Helen Hou-Sandà of the WordPress security team, Netanel Rubin of Check Point, and Ivan Grigorov. It also includes a fix for a potential timing side-channel attack, discovered by Johannes Schmitt of Scrutinizer, and prevents an attacker from locking a post from being edited, discovered by Mohamed A. Baset.
In addition to the security fixes, WordPress 4.2.4 contains fixes for 4 bugs:
* WPDB: When checking the encoding of strings against the database, make sure we're only relying on the return value of strings that were sent to the database. #32279
* Don't blindly trust the output of glob() to be an array. #33093
* Shortcodes: Handle do_shortcode('<[shortcode]') edge cases. #33116
* Shortcodes: Protect newlines inside of CDATA. #33106
Login to your web hosting control panel and navigate to the Installatron tool to update your installed applications.
End of report.