Releases: roots/wordpress
Release list
Version 7.0.2
Sourced from WordPress.org Documentation.
Summary
Security updates
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
- A facilitated SQL injection issue reported by as a team by TF1T, dtro, and haongo
- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber
As a courtesy, these fixes are available in affected branches of WordPress to eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported.
Version 6.9.5
Sourced from WordPress.org Documentation.
Summary
Security updates
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
- A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo
- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber
As a courtesy, these fixes are available in affected branches of WordPress to eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported.
Version 6.8.6
Sourced from WordPress.org Documentation.
Summary
Security updates
This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
- A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo
- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber
As a courtesy, these fixes are available in affected branches of WordPress to eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported.
Version 7.0.1
Sourced from WordPress.org Documentation.
Summary
This release was led by Aaron Jorbin, Brian Haas, Carlos Bravo and Estela Rueda.
This minor release includes fixes for 31 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress including the block editor, mail, and classic themes.
For a full list of bug fixes, please refer to the release candidate announcement.
Version 7.0
Sourced from WordPress.org Documentation.
Installation/Update Information
To download WordPress 7.0, update automatically from the Dashboard > Updates menu in your site’s admin area or visit the release archive.
For step-by-step instructions on installing and updating WordPress:
If you are new to WordPress, we recommend that you begin with the following:
Version 6.0.12
Version notes available on WordPress.org Documentation.
Version 5.2.24
Version notes available on WordPress.org Documentation.
Version 5.1.22
Version notes available on WordPress.org Documentation.
Version 5.0.25
Version notes available on WordPress.org Documentation.
Version 4.9.29
Version notes available on WordPress.org Documentation.