- WordPress versions 4.5.1 and earlier are affected by a SOME vulnerability through Plupload, the third-party library WordPress uses for uploading files.
- WordPress versions 4.2 through 4.5.1 are vulnerable to reflected XSS using specially crafted URIs through MediaElement.js, the third-party library used for media players.
We have released Bitnami WordPress 4.5.2 (and Multisite version) installers, virtual machines and cloud images that fix these issues.
Do you have questions about Bitnami WordPress or the security issue? Post to our community forum, and we will be happy to help you.