The security fixes in WordPress 3.6.1 are:
- Block unsafe PHP unserialization that could occur in limited situations and setups, which can lead to remote code execution.
- Prevent a user with an Author role, using a specially crafted request, from being able to create a post “written by” another user.
- Fix insufficient input validation that could result in redirecting or leading a user to another website.
Additionally, they also adjusted security restrictions around file uploads to mitigate potential cross-site scripting.
Among the 13 bugs, they fixed the jQuery 1.10.2.min.map 404 error which was causing the text editor to unresponsive. It was also breaking the comments on sites that used Jetpack comments. We got tons of reports regarding that, so we’re glad that it is fixed.
We strongly encourage you to upgrade your WordPress sites right now. Also don’t forget to create a backup just in case. If you do experience any problems, pleas open a ticket in our support forums so that we can fix it ASAP !
Download WordPress 3.6.1 or update now from the Dashboard -> Updates menu in your site's admin area.
For our Wordpress Themes and Wordpress Plugins: Every update, if available, will be announced in change-log.
Thanks for reading !