File: /home/wynnelaw5142/mail/new/1442733662.H450409P5973.p3plcpnl0292.prod.phx3.secureserver.net,S=2224
Return-path: <noreply@p3plcpnl0292.prod.phx3.secureserver.net>
Envelope-to: wynnelaw5142@p3plcpnl0292.prod.phx3.secureserver.net
Delivery-date: Sun, 20 Sep 2015 00:21:02 -0700
Received: from root by p3plcpnl0292.prod.phx3.secureserver.net with local (Exim 4.85)
(envelope-from <noreply@p3plcpnl0292.prod.phx3.secureserver.net>)
id 1ZdYvm-0001Xv-CO
for wynnelaw5142@p3plcpnl0292.prod.phx3.secureserver.net; Sun, 20 Sep 2015 00:21:02 -0700
To: wynnelaw5142@p3plcpnl0292.prod.phx3.secureserver.net
Subject: [Installatron] WordPress 4.3.1 now available (security release)
Date: Sun, 20 Sep 2015 09:21:02 +0200
From: noreply@p3plcpnl0292.prod.phx3.secureserver.net
Message-ID: <7232be87e5bba0157268f979d901dbdf@p3plcpnl0292.prod.phx3.secureserver.net>
X-Priority: 3
X-Mailer: Installatron Plugin 9.1.19
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
This is an automated email from Installatron. To unsubscribe from these emails or to change notification settings, login to your web hosting control panel, navigate to the Installatron tool, and select the installed applications you wish to modify.
An update to WordPress 4.3.1 (security release) is now available for the WordPress installations you are managing using Installatron. The following can be updated:
- http://www.wynnelawfirm.com
The changes for this version are:
This release addresses three issues, including two cross-site scripting vulnerabilities and a potential privilege escalation. We strongly encourage you to update your sites immediately.
Security
* WordPress versions 4.3 and earlier are vulnerable to a cross-site scripting vulnerability when processing shortcode tags (CVE-2015-5714). Reported by Shahar Tal and Netanel Rubin of Check Point.
* A separate cross-site scripting vulnerability was found in the user list table. Reported by Ben Bidner of the WordPress security team.
* Finally, in certain cases, users without proper permissions could publish private posts and make them sticky (CVE-2015-5715). Reported by Shahar Tal and Netanel Rubin of Check Point.
Login to your web hosting control panel and navigate to the Installatron tool to update your installed applications.
End of report.