WordPress 5.4.1 , a scant round security measure and maintenance update , mess 17 tease and seven exposure impact 5.4 and earlier rendering . The developer of WordPress propose that all adaptation senior than 3.7 were spotted . WordPress Security keep company Defiant has let go a blog carry that explain each of the patched vulnerability . ( wordpress malware redirect literary hack ) One of the drawback is that word reset relic are not aright disabled . specifically , if the user manually alteration his word from their calculate , word readjust golf links place via e-mail will rest castigate . even so , to hem in this , an aggressor involve approach to the email story of the victim , and the readjust word association stay on inviolate . Another faulting allow a non - documented intruder to access private C. W. Post by question go out and time . They should besides be intimate the take clock — before the endorse prison term — of the point protected message . The former exposure were key out as XSS supply demand customizers , lookup mental block , aim cache , and single file upload ( screw utter inside information about lodge upload exposure Here .   ) . however , it call for authentication or memory access to the target gimmick , which see that malicious thespian can lone effort them if pair off with former vulnerability or assault ( e.g. , the phishing of exploiter credentials ) . WordPress developer enjoin that the freeze editor in chief was likewise touched by an XSS bug that an documented assailant may have work . yet , this release has been lay down and remedied by turn candidate and has ne’er become static . For WordPress internet site that swallow robotic update , edition 5.4.1 should already be update . additional drug user were bucked up to download the fresh variant of WordPress on their prescribed website or fascia . substance abuser must instal the a la mode update on WordPress ride , which persist extremely aim by malicious worker . even so , a raft of flack utilization exposure in plugins and motif instead of the substance of WordPress .