There was an important WordPress security release today. Here’s the release notes:
— start —
WordPress 4.4.2 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately.
WordPress versions 4.4.1 and earlier are affected by two security issues: a possible SSRF for certain local URIs, reported by Ronni Skansing; and an open redirection attack, reported by Shailesh Suthar.
Thank you to both reporters for practicing responsible disclosure.
Download WordPress 4.4.2 or venture over to Dashboard → Updates and simply click “Update Now.” Sites that support automatic background updates are already beginning to update to WordPress 4.4.2.
— end —
As stated in the release, all WordPress users are advised to upgrade immediately to one of the following versions:
If you need assistance with upgrading, please contact Reliable Penguin at firstname.lastname@example.org or 866-649-7984.