Return-Path: <noreply@a2plcpnl0124.prod.iad2.secureserver.net>
Delivered-To: tredv4ubeawx@a2plcpnl0124.prod.iad2.secureserver.net
Received: from a2plcpnl0124.prod.iad2.secureserver.net
	by a2plcpnl0124.prod.iad2.secureserver.net with LMTP
	id IMMkFtC3ZGSq3zkAuWEn8Q
	(envelope-from <noreply@a2plcpnl0124.prod.iad2.secureserver.net>)
	for <tredv4ubeawx@a2plcpnl0124.prod.iad2.secureserver.net>; Wed, 17 May 2023 04:17:36 -0700
Return-path: <noreply@a2plcpnl0124.prod.iad2.secureserver.net>
Envelope-to: tredv4ubeawx@a2plcpnl0124.prod.iad2.secureserver.net
Delivery-date: Wed, 17 May 2023 04:17:36 -0700
Received: from root by a2plcpnl0124.prod.iad2.secureserver.net with local (Exim 4.95)
	(envelope-from <noreply@a2plcpnl0124.prod.iad2.secureserver.net>)
	id 1pzFA0-00FvEY-6m
	for tredv4ubeawx@a2plcpnl0124.prod.iad2.secureserver.net;
	Wed, 17 May 2023 04:17:36 -0700
To: tredv4ubeawx@a2plcpnl0124.prod.iad2.secureserver.net
Subject: [Installatron] WordPress 6.2.1 now available (security release)
Date: Wed, 17 May 2023 05:17:36 -0600
From: noreply@a2plcpnl0124.prod.iad2.secureserver.net
Message-ID: <d9aef53c01414c0941e0b3c6f6922e9b@a2plcpnl0124.prod.iad2.secureserver.net>
X-Mailer: Installatron Plugin 9.1.59 (278)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

This is an automated email from Installatron. To unsubscribe from these emails or to change notification settings, login to your web hosting control panel, navigate to the Installatron tool, and select the installed applications you wish to modify.

An update to WordPress 6.2.1 (security release) is now available for the WordPress installations you are managing using Installatron. The following can be updated:

- https://alisarefund.ca


The changes for this version are:

This minor release features 20 bug fixes in Core and 10 bug fixes for the block editor. This release also features several security fixes. 

Security
* Block themes parsing shortcodes in user generated data; thanks to Liam Gladdy of WP Engine for reporting this issue
* A CSRF issue updating attachment thumbnails; reported by John Blackbourn of the WordPress security team
* A flaw allowing XSS via open embed auto discovery; reported independently by Jakub Żoczek of Securitum and during a third party security audit
* Bypassing of KSES sanitization in block attributes for low privileged users; discovered during a third party security audit.
* A path traversal issue via translation files; reported independently by Ramuel Gall and during a third party security audit.

Login to your web hosting control panel and navigate to the Installatron tool to update your installed applications.

End of report.

