Title: Version 6.4.2
Author: Birgit Pauli-Haack
Published: December 6, 2023
Last modified: January 30, 2024

---

# Version 6.4.2

## In this article

 * [Installation/Update Information](https://wordpress.org/documentation/wordpress-version/version-6-4-2/?output_format=md#installation-update-information)
 * [Summary](https://wordpress.org/documentation/wordpress-version/version-6-4-2/?output_format=md#summary)
    - [Maintenance & Security updates](https://wordpress.org/documentation/wordpress-version/version-6-4-2/?output_format=md#maintenance-updates)
 * [Change log](https://wordpress.org/documentation/wordpress-version/version-6-4-2/?output_format=md#changelog)
    - [List of files revised](https://wordpress.org/documentation/wordpress-version/version-6-4-2/?output_format=md#list-of-files-revised)

[ Back to top](https://wordpress.org/documentation/wordpress-version/version-6-4-2/?output_format=md#wp--skip-link--target)

On December 6, 2023, WordPress 6.4.2 was released to the public.

## 󠀁[Installation/Update Information](https://wordpress.org/documentation/wordpress-version/version-6-4-2/?output_format=md#installation-update-information)󠁿

To get this version, update automatically from the Dashboard > Updates menu in your
site’s admin area or visit [https://wordpress.org/download/release-archive/](https://wordpress.org/download/release-archive/).

For step-by-step instructions on installing and updating WordPress:

 * [Updating WordPress](https://wordpress.org/documentation/article/updating-wordpress/)

If you are new to WordPress, we recommend that you begin with the following:

 * [New To WordPress – Where to Start](https://wordpress.org/support/article/new_to_wordpress_-_where_to_start/)
 * [First Steps With WordPress](https://wordpress.org/support/article/first-steps-with-wordpress/)
   or [Upgrading WordPress Extended](https://wordpress.org/documentation/article/upgrading-wordpress-extended-instructions/)
 * [WordPress Lessons](https://wordpress.org/support/article/wordpress-lessons/)

## 󠀁[Summary](https://wordpress.org/documentation/wordpress-version/version-6-4-2/?output_format=md#summary)󠁿

### 󠀁[Maintenance & Security updates](https://wordpress.org/documentation/wordpress-version/version-6-4-2/?output_format=md#maintenance-updates)󠁿

WordPress 6.4.2 fixes 7 Big fixes

 * [#59819](https://core.trac.wordpress.org/ticket/59819) – Change CSS align-item
   from start / end to flex-start / flex-end for full browser support
 * [#59821](https://core.trac.wordpress.org/ticket/59821) – Irrelevant comment for
   translators
 * [#59847](https://core.trac.wordpress.org/ticket/59847) – Since WordPress 6.4,
   the functions.php of a theme moved to a different location using register_theme_directory
   is no longer called
 * [#59869](https://core.trac.wordpress.org/ticket/59869) – Incorrect reference 
   in docblock for _register_theme_block_patterns
 * [#59882](https://core.trac.wordpress.org/ticket/59882) – Expose serialized template
   content to callbacks registered to the `hooked_block_types` filter.
 * [#59891](https://core.trac.wordpress.org/ticket/59891) – Incorrect example for
   WP_HTML_Tag_Processor class
 * [#59935](https://core.trac.wordpress.org/ticket/59935) – Site editor: logo

The security team addressed the following vulnerability in WordPress 6.4.2

 * A Remote Code Execution vulnerability that is not directly exploitable in core;
   however, the security team feels that there is a potential for high severity 
   when combined with some plugins, especially in multisite installations.

The 6.4.2 release was led by [@jorbin](https://profiles.wordpress.org/jorbin/).

**Thank you to everyone who contributed to WordPress 6.4.2**

[Aaron Jorbin](https://profiles.wordpress.org/jorbin), [Aki Hamano](https://profiles.wordpress.org/wildworks),
[Akira Tachibana](https://profiles.wordpress.org/atachibana), [Alex Concha](https://profiles.wordpress.org/xknown),
[Angela Jin](https://profiles.wordpress.org/angelasjin), [Anton Vlasenko](https://profiles.wordpress.org/antonvlasenko),
[Barry](https://profiles.wordpress.org/barry), [bernhard-reiter](https://profiles.wordpress.org/Bernhard%20Reiter),
[Caleb Burks](https://profiles.wordpress.org/icaleb), [Corey Worrell](https://profiles.wordpress.org/coreyw),
[crstauf](https://profiles.wordpress.org/crstauf), [Darren Ethier (nerrad)](https://profiles.wordpress.org/nerrad),
[David Baumwald](https://profiles.wordpress.org/davidbaumwald/), [Dennis Snell](https://profiles.wordpress.org/dmsnell),
[Dion Hulse](https://profiles.wordpress.org/dd32), [Erik](https://profiles.wordpress.org/kebbet),
[Fabian Todt](https://profiles.wordpress.org/gaambo), [Felix Arntz](https://profiles.wordpress.org/flixos90),
[Héctor Prieto](https://profiles.wordpress.org/priethor), [ironprogrammer](https://profiles.wordpress.org/ironprogrammer),
[Isabel Brison](https://profiles.wordpress.org/isabel_brison), [Jb Audras](https://profiles.wordpress.org/audrasjb),
[Jeffrey Paul](https://profiles.wordpress.org/jeffpaul), [Jessica Lyschik](https://profiles.wordpress.org/luminuu),
[Joe McGill](https://profiles.wordpress.org/joemcgill), [John Blackbourn](https://profiles.wordpress.org/johnbillion),
[Jonathan Desrosiers](https://profiles.wordpress.org/desrosj/), [Kharis Sulistiyono](https://profiles.wordpress.org/kharisblank),
[Krupal Panchal](https://profiles.wordpress.org/krupalpanchal), [Kylen Downs](https://profiles.wordpress.org/kdowns),
[meta4](https://profiles.wordpress.org/meta4), [Mike Schroder](https://profiles.wordpress.org/mikeschroder),
[Mukesh Panchal](https://profiles.wordpress.org/mukesh27), [partyfrikadelle](https://profiles.wordpress.org/partyfrikadelle),
[Peter Wilson](https://profiles.wordpress.org/peterwilsoncc), [Pieterjan Deneys](https://profiles.wordpress.org/NekoJonez),
[rawrly](https://profiles.wordpress.org/rawrly), [rebasaurus](https://profiles.wordpress.org/rebasaurus),
[Sergey Biryukov](https://profiles.wordpress.org/SergeyBiryukov), [Tonya Mork](https://profiles.wordpress.org/hellofromTonya),
[vortfu](https://profiles.wordpress.org/vortfu)

For more information, [browse the full list of changes on Trac](https://core.trac.wordpress.org/query?status=closed&resolution=fixed&milestone=6.4.2&order=priority).

## 󠀁[Change log](https://wordpress.org/documentation/wordpress-version/version-6-4-2/?output_format=md#changelog)󠁿

### 󠀁[List of files revised](https://wordpress.org/documentation/wordpress-version/version-6-4-2/?output_format=md#list-of-files-revised)󠁿

    ```wp-block-preformatted
    ./readme.html
    ./wp-admin/css/about-rtl.min.css
    ./wp-admin/css/about.css
    ./wp-admin/css/about-rtl.css
    ./wp-admin/css/about.min.css
    ./wp-admin/includes/update-core.php
    ./wp-admin/about.php
    ./wp-includes/theme.php
    ./wp-includes/ms-blogs.php
    ./wp-includes/html-api/class-wp-html-token.php
    ./wp-includes/html-api/class-wp-html-tag-processor.php
    ./wp-includes/version.php
    ./wp-includes/block-template-utils.php
    ./wp-includes/block-patterns.php
    ./wp-includes/rest-api/class-wp-rest-server.php
    ```

First published

December 6, 2023

Last updated

January 30, 2024