Shortly after our last update to WordPress 7.0.3 and Pressbooks 6.45 (to address the stored XSS issue in our built-in shortcodes), WordPress released 7.0.4, another security release.
What’s in WordPress 7.0.4
WordPress 7.0.4 fixes an authenticated Author-and-above remote code execution vulnerability, exploitable via malicious file upload on sites using Imagick and Ghostscript. As with any WordPress security release, immediate updating is recommended.
What We’ve Done
- Yesterday, we updated all of our networks to WordPress 7.0.4.
- We’ve released Pressbooks 6.45.1, which updates the minimum supported WordPress version to 7.0.4.
What You Should Do
If you’re running an open source, self-hosted instance of Pressbooks, we strongly recommend updating both WordPress to 7.0.4 and Pressbooks to 6.45.1 as soon as possible.
If you’re on Pressbooks-hosted infrastructure, no action is needed — you’re already covered.
As always, thank you for keeping your installs up to date and helping keep the Pressbooks community secure.