Version 4.0.24

On 5 July, 2018, WordPress 4.0.24 was released to the public.

Installation/Update Information

To download WordPress 4.0.24, update automatically from the Dashboard > Updates menu in your site’s admin area or visit https://wordpress.org/download/release-archive/.

For step-by-step instructions on installing and updating WordPress:

If you are new to WordPress, we recommend that you begin with the following:

Summary

From the WordPress 4.9.7 release post, WordPress versions 4.9.6 and earlier are affected by one security issue. As part of the core team’s ongoing commitment to security hardening, the following security and maintenance fixes have been implemented:

  1. WordPress versions 4.9.6 and earlier are affected by a file deletion issue where a user with the capability to edit and delete media files could potentially manipulate media metadata to attempt to delete files outside the uploads directory.
  2. Taxonomy: Improve cache handling for term queries.
  3. Posts, Post Types: Clear post password cookie when logging out.
  4. Widgets: Allow basic HTML tags in sidebar descriptions on Widgets admin screen.
  5. Community Events Dashboard: Always show the nearest WordCamp if one is coming up, even if there are multiple Meetups happening first.
  6. Privacy: Make sure default privacy policy content does not cause a fatal error when flushing rewrite rules outside of the admin context.

List of Files Revised

wp-includes/functions.php  
wp-includes/post.php

First published

Last updated