WordPress 5.7.2 is now available.
This security release features one security fix. Because this is a security release, it is recommended that you update your sites immediately. All versions since WordPress 3.7 have also been updated.
WordPress 5.7.2 is a short-cycle security release. The next major release will be version 5.8.
You can update to WordPress 5.7.2 by downloading from WordPress.org, or visit your Dashboard → Updates and click Update Now.
If you have sites that support automatic background updates, they’ve already started the update process.
Security Updates
One security issue affecting WordPress versions between 3.7 and 5.7. If you haven’t yet updated to 5.7, all WordPress versions since 3.7 have also been updated to fix the following security issue:
Object injection in PHPMailer, CVE-2020-36326 and CVE-2018-19296.
Thank you to the members of the WordPress security team for implementing these fixes in WordPress.
For more information refer to the version 5.7.2 HelpHub documentation page.
Thanks and props!
The 5.7.2 release was led by @peterwilsoncc and @audrasjb.
Thank you to everyone who helped make WordPress 5.7.2 happen: @audrasjb, @ayeshrajans, @desrosj, @dd32, @peterwilsoncc, @SergeyBiryukov, and @xknown.
More Stories
Monero 18.3.4 zero-day DoS vulnerability has been dropped publicly on social network.
Posted by upper.underflow via Fulldisclosure on Feb 16 Hello, About an hour ago, a group appearing to be named WyRCV2...
Netgear Router Administrative Web Interface Lacks Transport Encryption By Default
Posted by Ryan Delaney via Fulldisclosure on Feb 16 <!-- # Exploit Title: Netgear Router Administrative Web Interface Lacks Transport...
[CVE-2024-54756] GZDoom <= 4.13.1 Arbitrary Code Execution via Malicious ZScript
Posted by Gabriel Valachi via Fulldisclosure on Feb 15 In GZDoom 4.13.1 and below, there is a vulnerability involving array...
Re: Text injection on https://www.google.com/sorry/index via ?q parameter (no XSS)
Posted by David Fifield on Feb 15 Today at about 2025-02-13 19:00 I noticed the "≠" is back, but now...
python3.8-3.8.20-2.fc40
FEDORA-2025-b353a46e0c Packages in this update: python3.8-3.8.20-2.fc40 Update description: Security fixes for CVE-2024-11168 and CVE-2025-0938 Read More
python3.8-3.8.20-2.fc41
FEDORA-2025-bec494726c Packages in this update: python3.8-3.8.20-2.fc41 Update description: Security fixes for CVE-2024-11168 and CVE-2025-0938 Read More