WordPress announced today that it has released a critical security update for all its currently supported versions, and encourages everyone to update their websites immediately.
If you are still running WordPress 3.9 (or shamelessly still on 3.8 or 3.7), log into your WP control panel, then go to Dashboard > Updates to do your update now!
If you enabled the automatic update feature on your site, it should already be done. Log in anyway and check if you have the correct version (update versions are 3.9.2, 3.8.4 & 3.7.5). Why not make the jump to version 4.0.1 while you are at it; it’s seriously worth it.
Although not directly affected by the same vulnerabilities, If you are using WordPress 4.0 you will still want to update to 4.0.1 which fixes 23 bugs and takes care of 8 security issues.
Why Is This So Important?
Three cross-site scripting (XSS) issues were discovered. That should be enough to get you to make the update. “XSS enables attackers to inject client-side script into Web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls” (wikipedia).
All details on this update can be found in Andrew Nacin’s post.
