{"id":12946196,"date":"2020-06-10T17:21:24","date_gmt":"2020-06-10T17:21:24","guid":{"rendered":"https:\/\/wordpress.org\/support\/?post_type=helphub_version&amp;p=12946196"},"modified":"2020-06-10T17:21:24","modified_gmt":"2020-06-10T17:21:24","slug":"version-5-4-2","status":"publish","type":"helphub_version","link":"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-4-2\/","title":{"rendered":"Version 5.4.2"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On June 10, 2020, WordPress 5.4.2 was released to the public.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Installation\/Update Information<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To download WordPress 5.4.2, update automatically from the Dashboard &gt; Updates menu in your site\u2019s admin area or visit <a href=\"https:\/\/wordpress.org\/download\/release-archive\/\">WordPress releases archive<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For step-by-step instructions on installing and updating WordPress:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/wordpress.org\/documentation\/article\/updating-wordpress\/\">Updating WordPress<\/a><\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you are new to WordPress, we recommend that you begin with the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/wordpress.org\/documentation\/article\/new_to_wordpress_-_where_to_start\/\">New To WordPress \u2013 Where to Start<\/a><\/li><li><a href=\"https:\/\/wordpress.org\/documentation\/article\/first-steps-with-wordpress\/\">First Steps With WordPress<\/a>&nbsp;or&nbsp;<a href=\"https:\/\/wordpress.org\/documentation\/article\/upgrading-wordpress-extended-instructions\/\">Upgrading WordPress Extended<\/a><\/li><li><a href=\"https:\/\/wordpress.org\/documentation\/article\/wordpress-lessons\/\">WordPress Lessons<\/a><\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Summary<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Security updates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Five security issues affect WordPress versions 5.4 and earlier; version 5.4.2 fixes them, so you\u2019ll want to upgrade. If you haven\u2019t yet updated to 5.4, there are also updated versions of 5.3 and earlier that fix the security issues.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Props to Sam Thomas (jazzy2fives) for finding an XSS issue where authenticated users with low privileges are able to add JavaScript to posts in the block editor<\/li><li>Props to Luigi \u2013 (gubello.me) for discovering an XSS issue where authenticated users with upload permissions are able to add JavaScript to media files.<\/li><li>Props to Ben Bidner of the WordPress Security Team for finding an open redirect issue in\u00a0<em>wp_validate_redirect()<\/em><\/li><li>Props to\u00a0<a href=\"http:\/\/apapedulimu.click\/\">Nrimo Ing Pandum<\/a>\u00a0for finding an authenticated XSS issue via theme uploads<\/li><li>Props to\u00a0<a href=\"https:\/\/blog.ripstech.com\/authors\/simon-scannell\">Simon Scannell of RIPS Technologies<\/a>\u00a0for finding an issue where\u00a0<em>set-screen-option<\/em>\u00a0can be misused by plugins leading to privilege escalation<\/li><li>Props to\u00a0<a href=\"https:\/\/profiles.wordpress.org\/poena\/\">Carolina Nymark<\/a>\u00a0for discovering an issue where comments from password-protected posts and pages could be displayed under certain conditions.<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Maintenance updates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress 5.4.2 features&nbsp;<a href=\"https:\/\/core.trac.wordpress.org\/query?status=closed&amp;milestone=5.4.2&amp;group=status&amp;col=id&amp;col=summary&amp;col=status&amp;col=milestone&amp;col=owner&amp;col=type&amp;col=priority&amp;col=component&amp;col=focuses&amp;col=keywords&amp;order=priority\">22 bug and regression fixes<\/a>&nbsp;on both&nbsp;core&nbsp;and default themes.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49956\">49956<\/a>&nbsp;\u2013 Spammers able to share unmoderated comments <strong>(see related devnote below)<\/strong><\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49749\">49749<\/a>&nbsp;\u2013 Registering rest routes with a slash-prefixed namespace give inconsistent results<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49798\">49798<\/a>&nbsp;\u2013 Default WordPress favicon in dark mode browsers<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49808\">49808<\/a>&nbsp;\u2013 WordPress 5.4: Deprecated: tag_row_actions is deprecated since version 3.0.0<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/50121\">50121<\/a>&nbsp;\u2013 About page: correcting the order of headings<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/50131\">50131<\/a>&nbsp;\u2013 Absent custom favicon triggers wp-admin&nbsp;.htaccess\/.htpasswd prompt on frontend in FIrefox<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49353\">49353<\/a>&nbsp;\u2013 button padding issue in edit plug on small device<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/37926\">37926<\/a>&nbsp;\u2013 Twenty Eleven &amp; Twenty Twelve: Dropdown&nbsp;category&nbsp;widget&nbsp;exceeds parent div when strings are long enough<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/45865\">45865<\/a>&nbsp;\u2013 Twenty Nineteen: Consider decreasing the font size for widget titles<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/48803\">48803<\/a>&nbsp;\u2013 Twenty Twenty:&nbsp;Custom post type&nbsp;that doesn\u2019t support author, shows author<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/48916\">48916<\/a>&nbsp;\u2013 Twenty Twenty: anchor links don\u2019t work in mobile menu<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49088\">49088<\/a>&nbsp;\u2013 Twenty Twenty: Add icon for g.page links (Google business profile)<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49316\">49316<\/a>&nbsp;\u2013 Twenty Twenty missed license for images.<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49320\">49320<\/a>&nbsp;\u2013 Twenty Twenty: aligncenter&gt;figcaption missing text-align: center; feature<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49322\">49322<\/a>&nbsp;\u2013 Twenty Twenty: Submenu items disappear underneath the Cover&nbsp;block<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49435\">49435<\/a>&nbsp;\u2013 Twenty Twenty: inconsistent top and bottom margins for .alignwide and .alignfull on Chrome vs Safari (cross browser issue)<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49699\">49699<\/a>&nbsp;\u2013 Twenty Nineteen: Center- and right-aligned heading accents appear broken<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49793\">49793<\/a>&nbsp;\u2013 Twenty Twenty: Images in list blocks are not positioned correctly<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49893\">49893<\/a>&nbsp;\u2013 TwentyTwenty: TikTok and ResearchGate Social Icons<\/li><li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/49932\">49932<\/a>&nbsp;\u2013 Small Typo in Twenty-Twenty<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Thank you to everyone who contributed to WordPress 5.4.2:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/profiles.wordpress.org\/afercia\/\">Andrea Fercia<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/argentite\/\">argentite<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/asif2bd\/\">M Asif Rahman<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/audrasjb\/\">Jb Audras<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ayeshrajans\/\">Ayesh Karunaratne<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/bdcstr\/\">bdcstr<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/delowardev\/\">Delowar Hossain<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/dhrrob\/\">Rob Migchels<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/donmhico\/\">donmhico<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/emlebrun\/\">Emilie LEBRUN<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/finomeno\/\">finomeno<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/garethgillman\/\">garethgillman<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/giorgio25b\/\">Giorgio25b<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/gma992\/\">Gabriel Maldonado<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/h71\/\">Hector F<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ianbelanger\/\">Ian Belanger<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/imath\/\">Mathieu Viet<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/javiercasares\/\">Javier Casares<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/joemcgill\/\">Joe McGill<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jonkolbert\/\">jonkolbert<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jonoaldersonwp\/\">Jono Alderson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/joyously\/\">Joy<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/karmatosed\/\">Tammie Lister<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/kjellr\/\">Kjell Reigstad<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/kthmd\/\">KT<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/markusthiel\/\">markusthiel<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mayankmajeji\/\">Mayank Majeji<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/melchoyce\/\">Mel Choyce-Dwan<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mislavjuric\/\">mislavjuric<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mukesh27\/\">Mukesh Panchal<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/nikhilbhansi\/\">Nikhil Bhansi<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/oakesjosh\/\">oakesjosh<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ocean90\/\">Dominik Schilling<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/passoniate\/\">Arslan Ahmed<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/peterwilsoncc\/\">Peter Wilson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/poena\/\">Carolina Nymark<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/sabernhardt\/\">Stephen Bernhardt<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/samful\/\">Sam Fullalove<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/schlessera\/\">Alain Schlesser<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/sergeybiryukov\/\">Sergey Biryukov<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/skarabeq\/\">skarabeq<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/skithund\/\">Toni Viemer\u00f6<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/suzylah\/\">suzylah<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/timothyblynjacobs\/\">Timothy Jacobs<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/utz119\/\">TeBenachi<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/whyisjake\/\">Jake Spurlock<\/a> and <a href=\"https:\/\/profiles.wordpress.org\/yuhin\/\">yuhin<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For more information,&nbsp;<a href=\"https:\/\/core.trac.wordpress.org\/query?status=closed&amp;milestone=5.4.2&amp;group=status&amp;col=id&amp;col=summary&amp;col=status&amp;col=milestone&amp;col=owner&amp;col=type&amp;col=priority&amp;col=component&amp;col=focuses&amp;col=keywords&amp;order=priority\">browse the full list of changes on Trac<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Notes for developers<\/h2>\n\n\n\n<figure class=\"wp-block-embed-wordpress wp-block-embed is-type-wp-embed is-provider-make-wordpress-core\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"8mtIBocJ6i\"><a href=\"https:\/\/make.wordpress.org\/core\/2020\/06\/09\/wordpress-5-4-2-prevent-unmoderated-comments-from-search-engine-indexation\/\">WordPress 5.4.2: Prevent unmoderated comments from search engine indexation<\/a><\/blockquote><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;WordPress 5.4.2: Prevent unmoderated comments from search engine indexation&#8221; &#8212; Make WordPress Core\" src=\"https:\/\/make.wordpress.org\/core\/2020\/06\/09\/wordpress-5-4-2-prevent-unmoderated-comments-from-search-engine-indexation\/embed\/#?secret=BtKVKOLbyZ#?secret=8mtIBocJ6i\" data-secret=\"8mtIBocJ6i\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">List of Files Revised<\/h2>\n\n\n\n<pre class=\"wp-block-preformatted\">wp-admin\/about.php\nwp-admin\/themes.php\nwp-admin\/css\/common.css\nwp-admin\/images\/w-logo-blue.png\nwp-admin\/includes\/class-wp-site-health.php\nwp-admin\/includes\/class-wp-terms-list-table.php\nwp-admin\/includes\/media.php\nwp-admin\/includes\/misc.php\nwp-admin\/includes\/theme.php\nwp-content\/themes\/twentyeleven\/style.css\nwp-content\/themes\/twentynineteen\/sass\/mixins\/_mixins-master.scss\nwp-content\/themes\/twentynineteen\/sass\/site\/secondary\/_widgets.scss\nwp-content\/themes\/twentynineteen\/style-editor.css\nwp-content\/themes\/twentynineteen\/style-rtl.css\nwp-content\/themes\/twentynineteen\/style.css\nwp-content\/themes\/twentytwelve\/style.css\nwp-content\/themes\/twentytwenty\/assets\/js\/index.js\nwp-content\/themes\/twentytwenty\/classes\/class-twentytwenty-svg-icons.php\nwp-content\/themes\/twentytwenty\/inc\/template-tags.php\nwp-content\/themes\/twentytwenty\/readme.txt\nwp-content\/themes\/twentytwenty\/style-rtl.css\nwp-content\/themes\/twentytwenty\/style.css\nwp-content\/themes\/twentytwenty\/template-parts\/content-cover.php\nwp-content\/themes\/twentytwenty\/template-parts\/content.php\nwp-includes\/class-walker-comment.php\nwp-includes\/class-wp-comment-query.php\nwp-includes\/class-wp.php\nwp-includes\/comment-template.php\nwp-includes\/comment.php\nwp-includes\/default-filters.php\nwp-includes\/embed.php\nwp-includes\/functions.php\nwp-includes\/images\/w-logo-blue-white-bg.png\nwp-includes\/pluggable.php\nwp-includes\/rest-api.php\nwp-includes\/version.php\npackage-lock.json\npackage.json\nwp-comments-post.php<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Updated packages<\/h2>\n\n\n\n<pre class=\"wp-block-preformatted\">@wordpress\/block-library: 2.4.7\n@wordpress\/edit-post: 3.3.7<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>On June 10, 2020, WordPress 5.4.2 was released to the public. Installation\/Update Information To download WordPress 5.4.2, update automatically from the Dashboard &gt; Updates menu in your site\u2019s admin area or visit WordPress releases archive. For step-by-step instructions on installing and updating WordPress: Updating WordPress If you are new to WordPress, we recommend that you [&hellip;]<\/p>\n","protected":false},"author":8670591,"featured_media":0,"menu_order":0,"template":"","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false},"helphub_major_release":[65],"class_list":["post-12946196","helphub_version","type-helphub_version","status-publish","hentry","helphub_major_release-5_4"],"revision_note":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/12946196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions"}],"about":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/types\/helphub_version"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/users\/8670591"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/12946196\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/media?parent=12946196"}],"wp:term":[{"taxonomy":"helphub_major_release","embeddable":true,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/helphub_major_release?post=12946196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}