Four security issues affect WordPress versions 5.1.3 and earlier; version 5.1.4 fixes them, so you’ll want to upgrade.
Props to Daniel Bachhuber for finding an issue where an unprivileged user could make a post sticky via the REST API.
Props to Simon Scannell of RIPS Technologies for finding and disclosing an issue where cross-site scripting (XSS) could be stored in well-crafted links.
Props to the WordPress.org Security Team for hardening wp_kses_bad_protocol() to ensure that it is aware of the named colon attribute.
Props to Nguyen The Duc for discovering a stored XSS vulnerability using block editor content.
This update has been submitted for testing by remi.
This update has been submitted for testing by remi.
This update's test gating status has been changed to 'waiting'.
This update's test gating status has been changed to 'ignored'.
This update has been pushed to testing.
This update can be pushed to stable now if the maintainer wishes
This update has been submitted for stable by bodhi.
This update has been pushed to stable.