{"id":16106412,"date":"2022-10-17T22:50:09","date_gmt":"2022-10-17T22:50:09","guid":{"rendered":"https:\/\/wordpress.org\/support\/?post_type=helphub_version&#038;p=16106412"},"modified":"2023-05-17T09:23:21","modified_gmt":"2023-05-17T09:23:21","slug":"version-6-0-3","status":"publish","type":"helphub_version","link":"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-0-3\/","title":{"rendered":"Version 6.0.3"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On October 17, 2022, WordPress 6.0.3 was released to the public. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"installation-update-information\">Installation\/Update Information<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To get this version, update automatically from the Dashboard &gt; Updates menu in your site&#8217;s admin area or visit <a href=\"https:\/\/wordpress.org\/download\/release-archive\/\">https:\/\/wordpress.org\/download\/release-archive\/<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For step-by-step instructions on installing and updating WordPress:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/updating-wordpress\/\">Updating WordPress<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you are new to WordPress, we recommend that you begin with the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"\/support\/article\/new_to_wordpress_-_where_to_start\/\">New To WordPress &#8211; Where to Start<\/a><\/li>\n\n\n\n<li><a href=\"\/support\/article\/first-steps-with-wordpress\/\">First Steps With WordPress<\/a> or <a href=\"https:\/\/wordpress.org\/documentation\/article\/upgrading-wordpress-extended-instructions\/\">Upgrading WordPress Extended<\/a><\/li>\n\n\n\n<li><a href=\"\/support\/article\/wordpress-lessons\/\">WordPress Lessons<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"summary\">Summary<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Security updates included in this release<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Stored XSS via wp-mail.php (post by email) &#8211; Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. via JPCERT<\/li>\n\n\n\n<li>Open redirect in `wp_nonce_ays` &#8211; <a href=\"https:\/\/hackerone.com\/devrayn\">devrayn<\/a><\/li>\n\n\n\n<li>Sender&#8217;s email address is exposed in wp-mail.php &#8211; Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. via JPCERT<\/li>\n\n\n\n<li>Media Library &#8211; Reflected XSS via SQLi &#8211; Ben Bidner from the WordPress security team and Marc Montpas from Automattic independently discovered this issue<\/li>\n\n\n\n<li>CSRF in wp-trackback.php &#8211; Simon Scannell<\/li>\n\n\n\n<li>Stored XSS via the Customizer &#8211; Alex Concha from the WordPress security team<\/li>\n\n\n\n<li>Revert shared user instances introduced in <a href=\"https:\/\/core.trac.wordpress.org\/changeset\/50790\">50790<\/a> &#8211; Alex Concha and Ben Bidner from the WordPress security team<\/li>\n\n\n\n<li>Stored XSS in WordPress Core via Comment Editing &#8211; Third-party security audit and Alex Concha from the WordPress security team<\/li>\n\n\n\n<li>Data exposure via the REST Terms\/Tags Endpoint &#8211; Than Taintor<\/li>\n\n\n\n<li>Content from multipart emails leaked &#8211; <a href=\"https:\/\/profiles.wordpress.org\/kraftner\">Thomas Kr\u00e4ftner<\/a><\/li>\n\n\n\n<li>SQL Injection due to improper sanitization in `WP_Date_Query` &#8211; <a href=\"https:\/\/www.gold-network.ch\">Michael Mazzolini<\/a><\/li>\n\n\n\n<li>RSS Widget: Stored XSS issue &#8211; Third-party security audit<\/li>\n\n\n\n<li>Stored XSS in the search block &#8211; Alex Concha of the WP Security team<\/li>\n\n\n\n<li>Feature Image Block: XSS issue &#8211; Third-party security audit<\/li>\n\n\n\n<li>RSS Block: Stored XSS issue &#8211; Third-party security audit<\/li>\n\n\n\n<li>Fix widget block XSS &#8211; Third-party security audit<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"credits\">Credits<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This release was led by <a href=\"https:\/\/profiles.wordpress.org\/xknown\">Alex Concha<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/peterwilsoncc\">Peter Wilson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/audrasjb\">Jb Audras<\/a>, and <a href=\"https:\/\/profiles.wordpress.org\/SergeyBiryukov\">Sergey Biryukov<\/a>. Thanks to <a href=\"https:\/\/profiles.wordpress.org\/desrosj\/\">Jonathan Desrosiers<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jorgefilipecosta\/\">Jorge Costa<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/bernhard-reiter\/\">Bernie Reiter<\/a> and <a href=\"https:\/\/profiles.wordpress.org\/cbravobernal\/\">Carlos Bravo<\/a> for their help on package updates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress 6.0.3 would not have been possible without the contributions of the following people. Their asynchronous coordination to deliver several fixes into a stable release is a testament to the power and capability of the WordPress community.<\/p>\n\n\n\n<p class=\"is-style-default wp-block-paragraph\"><a href=\"https:\/\/profiles.wordpress.org\/xknown\/\">Alex Concha<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/costdev\/\">Colin Stewart<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/talldanwp\/\">Daniel Richards<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/davidbaumwald\/\">David Baumwald<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/dd32\/\">Dion Hulse<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/ehtis\/\">ehtis<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/voldemortensen\/\">Garth Mortensen<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/audrasjb\/\">Jb Audras<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/johnbillion\/\">John Blackbourn<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/johnjamesjacoby\/\">John James Jacoby<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/desrosj\/\">Jonathan Desrosiers<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jorgefilipecosta\/\">Jorge Costa<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/jrf\/\">Juliette Reinders Folmer<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/rudlinkon\/\">Linkon Miyan<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/martinkrcho\/\">martin.krcho<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/matveb\/\">Matias Ventura<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/mukesh27\/\">Mukesh Panchal<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/paulkevan\/\">Paul Kevan<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/peterwilsoncc\/\">Peter Wilson<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/noisysocks\/\">Robert Anderson<\/a><a href=\"https:\/\/profiles.wordpress.org\/robinwpdeveloper\/\">Robin<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/sergeybiryukov\/\">Sergey Biryukov<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/sumitbagthariya16\/\">Sumit Bagthariya<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/tykoted\/\">Teddy Patriarca<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/timothyblynjacobs\/\">Timothy Jacobs<\/a>, <a href=\"https:\/\/profiles.wordpress.org\/vortfu\/\">vortfu<\/a>, and <a href=\"https:\/\/profiles.wordpress.org\/chesio\/\">\u010ceslav Przywara<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"list-of-updated-packages\">List of updated packages<\/h2>\n\n\n\n<pre class=\"wp-block-preformatted\">@wordpress\/block-directory: 3.4.15\n@wordpress\/block-library: 7.3.15\n@wordpress\/customize-widgets: 3.3.15\n@wordpress\/edit-post: 6.3.15\n@wordpress\/edit-site: 4.3.15\n@wordpress\/edit-widgets: 4.3.15\n@wordpress\/widgets: 2.4.11<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"list-of-files-revised\">List of Files Revised<\/h2>\n\n\n\n<pre class=\"wp-block-preformatted\">src\/wp-admin\/about.php\nsrc\/wp-admin\/includes\/ajax-actions.php\nsrc\/wp-admin\/includes\/post.php\nsrc\/wp-includes\/blocks\/legacy-widget.php\nsrc\/wp-includes\/blocks\/navigation.php\nsrc\/wp-includes\/blocks\/post-featured-image.php\nsrc\/wp-includes\/blocks\/rss.php\nsrc\/wp-includes\/blocks\/search.php\nsrc\/wp-includes\/blocks\/widget-group.php\nsrc\/wp-includes\/class-wp-date-query.php\nsrc\/wp-includes\/class-wp-query.php\nsrc\/wp-includes\/comment.php\nsrc\/wp-includes\/customize\/class-wp-customize-header-image-control.php\nsrc\/wp-includes\/customize\/class-wp-customize-site-icon-control.php\nsrc\/wp-includes\/deprecated.php\nsrc\/wp-includes\/functions.php\nsrc\/wp-includes\/media-template.php\nsrc\/wp-includes\/pluggable.php\nsrc\/wp-includes\/post.php\nsrc\/wp-includes\/rest-api\/endpoints\/class-wp-rest-attachments-controller.php\nsrc\/wp-includes\/rest-api\/endpoints\/class-wp-rest-terms-controller.php\nsrc\/wp-includes\/user.php\nsrc\/wp-includes\/version.php\nsrc\/wp-includes\/widgets.php\nsrc\/wp-mail.php\nsrc\/wp-trackback.php<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>On October 17, 2022, WordPress 6.0.3 was released to the public. Installation\/Update Information To get this version, update automatically from the Dashboard &gt; Updates menu in your site&#8217;s admin area or visit https:\/\/wordpress.org\/download\/release-archive\/. For step-by-step instructions on installing and updating WordPress: If you are new to WordPress, we recommend that you begin with the following: [&hellip;]<\/p>\n","protected":false},"author":14331594,"featured_media":0,"menu_order":0,"template":"","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false},"helphub_major_release":[71],"class_list":["post-16106412","helphub_version","type-helphub_version","status-publish","hentry","helphub_major_release-6-0"],"revision_note":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16106412","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions"}],"about":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/types\/helphub_version"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/users\/14331594"}],"version-history":[{"count":2,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16106412\/revisions"}],"predecessor-version":[{"id":16357001,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16106412\/revisions\/16357001"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/media?parent=16106412"}],"wp:term":[{"taxonomy":"helphub_major_release","embeddable":true,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/helphub_major_release?post=16106412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}