
====================================================================

                             CERT-Renater

                 Note d'Information No. 2019/VULN413
_____________________________________________________________________

DATE                : 16/12/2019

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running WordPress versions prior to 5.3.1.

=====================================================================
https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/
_____________________________________________________________________

WordPress 5.3.1 Security and Maintenance Release
Posted December 13, 2019 by Jb Audras. Filed under Releases, Security.

WordPress 5.3.1 is now available!

This security and maintenance release features 46 fixes and
enhancements. Plus, it adds a number of security fixes—see the list
below.

WordPress 5.3.1 is a short-cycle maintenance release. The next major
release will be version 5.4.

You can download WordPress 5.3.1 by clicking the button at the top of
this page, or visit your Dashboard → Updates and click Update Now.

If you have sites that support automatic background updates, they’ve
already started the update process.


Security updates

Four security issues affect WordPress versions 5.3 and earlier; version
5.3.1 fixes them, so you’ll want to upgrade. If you haven’t yet updated
to 5.3, there are also updated versions of 5.2 and earlier that fix the
security issues.

    Props to Daniel Bachhuber for finding an issue where an unprivileged
user could make a post sticky via the REST API.

    Props to Simon Scannell of RIPS Technologies for finding and
disclosing an issue where cross-site scripting (XSS) could be stored in
well-crafted links.

    Props to the WordPress.org Security Team for hardening
wp_kses_bad_protocol() to ensure that it is aware of the named colon
attribute.

    Props to Nguyen The Duc for discovering a stored XSS vulnerability
using block editor content.


Maintenance updates

Here are a few of the highlights:

    Administration: improvements to admin form controls height and
alignment standardization (see related dev note), dashboard widget links
accessibility and alternate color scheme readability issues (see related
dev note).
    Block editor: fix Edge scrolling issues and intermittent JavaScript
issues.
    Bundled themes: add customizer option to show/hide author bio,
replace JS based smooth scroll with CSS (see related dev note) and fix
Instagram embed CSS.
    Date/time: improve non-GMT dates calculation, fix date format output
in specific languages and make get_permalink() more resilient against
PHP timezone changes.
    Embeds: remove CollegeHumor oEmbed provider as the service doesn’t
exist anymore.
    External libraries: update sodium_compat.
    Site health: allow the remind interval for the admin email
verification to be filtered.
    Uploads: avoid thumbnails overwriting other uploads when filename
matches, and exclude PNG images from scaling after upload.
    Users: ensure administration email verification uses the user’s
locale instead of the site locale.

For more information, browse the full list of changes on Trac or check
out the version 5.3.1 HelpHub documentation page.
Thanks!

In addition to the security researchers mentioned above, thank you to
everyone who contributed to WordPress 5.3.1:

123host, acosmin, Adam Silverstein, Albert Juhé Lluveras, Alex Concha,
Alex Mills, Anantajit JG, Anders Norén, andraganescu, Andrea Fercia,
Andrew Duthie, Andrew Ozz, Andrey “Rarst” Savchenko, aravindajith,
archon810, Ate Up With Motor, Ayesh Karunaratne, Birgir Erlendsson
(birgire), Boga86, Boone Gorges, Carolina Nymark, Chetan Prajapati,
Csaba (LittleBigThings), Dademaru, Daniel Bachhuber, Daniele
Scasciafratte, Daniel Richards, David Baumwald, David Herrera, Dion
hulse, ehtis, Ella van Durpe, epiqueras, Fabian, Felix Arntz,
flaviozavan, Garrett Hyder, Glenn, Grzegorz (Greg) Ziółkowski,
Grzegorz.Janoszka, Hareesh Pillai, Ian Belanger, ispreview, Jake
Spurlock, James Huff, James Koster, Jarret, Jasper van der Meer, Jb
Audras, jeichorn, Jer Clarke, Jeremy Felt, Jip Moors, Joe Hoyle, John
James Jacoby, Jonathan Desrosiers, Jonny Harris, Joost de Valk, Jorge
Costa, Joy, Juliette Reinders Folmer, justdaiv, Kelly Dwan, Kharis
Sulistiyono, Kite, kyliesabra, lisota, lukaswaudentio, Maciej Mackowiak,
marcelo2605, Marius L. J., Mat Lipe, mayanksonawat, Mel Choyce-Dwan,
Michael Arestad, miette49, Miguel Fonseca, mihdan, Mike Auteri, Mikko
Saari, Milan Petrovic, Mukesh Panchal, NextScripts, Nick Daugherty,
Niels Lange, noyle, Ov3rfly, Paragon Initiative Enterprises, Paul Biron,
Peter Wilson, Rachel Peter, Riad Benguella, Ricard Torres, Roland Murg,
Ryan McCue, Ryan Welcher, SamuelFernandez, sathyapulse, Scott Taylor,
scvleon, Sergey Biryukov, sergiomdgomes, SGr33n, simonjanin, smerriman,
steevithak, Stephen Bernhardt, Stephen Edgar, Steve Dufresne, Subrata
Mal, Sultan Nasir Uddin, Sybre Waaijer, Tammie Lister, Tanvirul Haque,
Tellyworth, timon33, Timothy Jacobs, Timothée Brosille, tmatsuur, Tung
Du, Veminom, vortfu, waleedt93, williampatton, wpgurudev, and Zack
Tollman.

=========================================================
+ CERT-RENATER        | tel : 01-53-94-20-44            +
+ 23/25 Rue Daviel    | fax : 01-53-94-20-41            +
+ 75013 Paris         | email:cert@support.renater.fr   +
=========================================================



