

A flaw allowing XSS via open embed auto discovery reported independently by Jakub Żoczek of Securitum and during a third party security audit.A CSRF issue updating attachment thumbnails reported by John Blackbourn of the WordPress security team.


A flaw allowing XSS via open embed auto discovery reported independently by Jakub Żoczek of Securitum and during a third party security audit.A CSRF issue updating attachment thumbnails reported by John Blackbourn of the WordPress security team.