WordPress Managed - Package updates
Pinned
WordPress (Managed)
-
[2.19.0]
- Update WordPress to 5.8
- Release announcement
- Manage Widgets with Blocks
- Display Posts with New Blocks and Patterns
- Edit the Templates Around Posts
- Overview of the Page Structure
- Suggested Patterns for Blocks
- Style and Colorize Images
-
[2.20.0]
- Update WordPress to 5.8.1
- Make sendmail optional
- Release announcement
- Props @mdawaffe, member of the WordPress Security Team for their work fixing a data exposure vulnerability within the REST API.
- Props to Bentkowski of Securitum for reporting a XSS vulnerability in the block editor.
- The Lodash library has been updated to version 4.17.21 in each branch to incorporate upstream security fixes.
-
[2.20.2]
- Update WordPress to 5.8.3
- Release announcement
- Props to Karim El Ouerghemmi and Simon Scannell of SonarSource for disclosing an issue with stored XSS through post slugs.
- Props to Simon Scannell of SonarSource for reporting an issue with Object injection in some multisite installations.
- Props to ngocnb and khuyenn from GiaoHangTietKiem JSC for working with Trend Micro Zero Day Initiative on reporting a SQL injection vulnerability in WP_Query.
- Props to Ben Bidner from the WordPress security team for reporting a SQL injection vulnerability in WP_Meta_Query (only relevant to versions 4.1-5.8).
-
[2.24.0]
- Update WordPress to 6.0.1
- Release announcement
- Email Display Name support . Please note that you have to set any custom mail from display name in the Email section.
-
[2.24.1]
- Update WordPress to 6.0.2
- Release announcement
- #56112 – Allow remote pattern registration in theme.json when core patterns are disabled
- #56184 – register_block_type does not recognise “ancestor” block setting
- #56210 – What’s new page design issue in core wordpress
- #56225 –
@since 6.1.0
appearing in 6.0.1
-
[2.24.3]
- Update WordPress to 6.0.3
- Release announcement
- Stored XSS via wp-mail.php (post by email) – Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. via JPCERT
- Open redirect in
wp_nonce_ays
– devrayn - Sender’s email address is exposed in wp-mail.php – Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. via JPCERT
- Media Library – Reflected XSS via SQLi – Ben Bidner from the WordPress security team and Marc Montpas from Automattic independently discovered this issue
-
[2.25.0]
- Update WordPress to 6.1
- Release announcement
- Twenty Twenty-Three: A fresh default theme with 10 distinct style variations
- New templates for an improved creator experience
- Design tools for more consistency and control
- Manage menus with ease
- Cleaner layouts and document settings visualization
- One-click lock setting for all inner blocks
- Improved block placeholders
- Compose richer lists and quotes with inner blocks
- More Responsive text with fluid typography
- Add starter patterns to any post type
- A streamlined style system