WordPress 4.9.5 was released yesterday. You can read all the details here.
WordPress versions 4.9.4 and earlier are affected by three security issues. As part of the core team’s ongoing commitment to security hardening, the following fixes have been implemented in 4.9.5:
- Don’t treat
localhostas same host by default.
- Use safe redirects when redirecting the login page if SSL is forced.
- Make sure the version string is correctly escaped for use in generator tags.
25 other bugs were fixed in WordPress 4.9.5. Particularly of note were:
- The previous styles on caption shortcodes have been restored.
- Cropping on touch screen devices is now supported.
- A variety of strings such as error messages have been updated for better clarity.
- The position of an attachment placeholder during uploads has been fixed.
- Improved compatibility with PHP 7.2.
You can read all the details about the release here.
Go ahead and update to 4.9.5 today!