Skip to content

1.0.7

Compare
Choose a tag to compare
@websevendev websevendev released this 31 Aug 16:30
· 2 commits to main since this release
  • Security update: users without unfiltered_html capability can no longer add attributes. When a user without the capability updates a post all existing attributes are stripped. Issue discovered by Francesco Carlucci (CVE ID: CVE-2024-8318, CVSS Severity Score: 6.4 (Medium)). The vulnerability made it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accessed an injected page.
  • Tested up to WordPress 6.6.
  • Update @wordpress/* packages.