From the WordPress 4.9.7 release post, WordPress versions 4.9.6 and earlier are affected by one security issue. As part of the core team’s ongoing commitment to security hardening, the following security and maintenance fixes have been implemented:
- WordPress versions 4.9.6 and earlier are affected by a file deletion issue where a user with the capability to edit and delete media files could potentially manipulate media metadata to attempt to delete files outside the uploads directory.
- Taxonomy: Improve cache handling for term queries.
- Posts, Post Types: Clear post password cookie when logging out.
- Widgets: Allow basic HTML tags in sidebar descriptions on Widgets admin screen.
- Community Events Dashboard: Always show the nearest WordCamp if one is coming up, even if there are multiple Meetups happening first.
List of Files Revised
wp-admin/about.php wp-admin/edit-form-comment.php wp-admin/includes/class-wp-community-events.php wp-admin/includes/file.php wp-admin/includes/misc.php wp-admin/includes/plugin.php wp-admin/includes/template.php wp-admin/includes/user.php wp-admin/privacy.php wp-includes/class-wp-term-query.php wp-includes/comment-template.php wp-includes/functions.php wp-includes/pluggable.php wp-includes/post.php wp-includes/user.php wp-includes/version.php wp-includes/widgets.php