{"id":16106607,"date":"2022-10-17T14:41:02","date_gmt":"2022-10-17T14:41:02","guid":{"rendered":"https:\/\/wordpress.org\/support\/?post_type=helphub_version&amp;p=16106607"},"modified":"2022-10-17T14:41:02","modified_gmt":"2022-10-17T14:41:02","slug":"version-5-8-6","status":"publish","type":"helphub_version","link":"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-5-8-6\/","title":{"rendered":"Version 5.8.6"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On October 17, 2022, WordPress 5.8.5 was released to the public. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"installation-update-information\">Installation\/Update Information<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To get this version, update automatically from the Dashboard &gt; Updates menu in your site&#8217;s admin area or visit <a href=\"https:\/\/wordpress.org\/download\/release-archive\/\">https:\/\/wordpress.org\/download\/release-archive\/<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For step-by-step instructions on installing and updating WordPress:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/updating-wordpress\/\">Updating WordPress<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you are new to WordPress, we recommend that you begin with the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"\/support\/article\/new_to_wordpress_-_where_to_start\/\">New To WordPress &#8211; Where to Start<\/a><\/li>\n\n\n\n<li><a href=\"\/support\/article\/first-steps-with-wordpress\/\">First Steps With WordPress<\/a> or <a href=\"https:\/\/wordpress.org\/documentation\/article\/upgrading-wordpress-extended-instructions\/\">Upgrading WordPress Extended<\/a><\/li>\n\n\n\n<li><a href=\"\/support\/article\/wordpress-lessons\/\">WordPress Lessons<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"summary\">Summary<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">Security updates included in this release<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Stored XSS via wp-mail.php (post by email) &#8211; Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. via JPCERT<\/li>\n\n\n\n<li>Open redirect in `wp_nonce_ays` &#8211; <a href=\"https:\/\/hackerone.com\/devrayn\">devrayn<\/a><\/li>\n\n\n\n<li>Sender&#8217;s email address is exposed in wp-mail.php &#8211; Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. via JPCERT<\/li>\n\n\n\n<li>Media Library &#8211; Reflected XSS via SQLi &#8211; Ben Bidner from the WordPress security team and Marc Montpas from Automattic independently discovered this issue<\/li>\n\n\n\n<li>CSRF in wp-trackback.php &#8211; Simon Scannell<\/li>\n\n\n\n<li>Stored XSS via the Customizer &#8211; Alex Concha from the WordPress security team<\/li>\n\n\n\n<li>Revert shared user instances introduced in <a href=\"https:\/\/core.trac.wordpress.org\/changeset\/50790\">50790<\/a> &#8211; Alex Concha and Ben Bidner from the WordPress security team<\/li>\n\n\n\n<li>Stored XSS in WordPress Core via Comment Editing &#8211; Third-party security audit and Alex Concha from the WordPress security team<\/li>\n\n\n\n<li>Data exposure via the REST Terms\/Tags Endpoint &#8211; Than Taintor<\/li>\n\n\n\n<li>Content from multipart emails leaked &#8211; <a href=\"https:\/\/profiles.wordpress.org\/kraftner\">Thomas Kr\u00e4ftner<\/a><\/li>\n\n\n\n<li>SQL Injection due to improper sanitization in `WP_Date_Query` &#8211; <a href=\"https:\/\/www.gold-network.ch\">Michael Mazzolini<\/a><\/li>\n\n\n\n<li>RSS Widget: Stored XSS issue &#8211; Third-party security audit<\/li>\n\n\n\n<li>Stored XSS in the search block &#8211; Alex Concha of the WP Security team<\/li>\n\n\n\n<li>Feature Image Block: XSS issue &#8211; Third-party security audit<\/li>\n\n\n\n<li>RSS Block: Stored XSS issue &#8211; Third-party security audit<\/li>\n\n\n\n<li>Fix widget block XSS &#8211; Third-party security audit<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"credits\">Credits<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This release was led by Alex Concha (<a href=\"https:\/\/profiles.wordpress.org\/xknown\">@xknown<\/a>), Peter Wilson (<a href=\"https:\/\/profiles.wordpress.org\/peterwilsoncc\">@peterwilsoncc<\/a>), Jb Audras (<a href=\"https:\/\/profiles.wordpress.org\/audrasjb\">@audrasjb<\/a>), and Sergey Biryukov (<a href=\"https:\/\/profiles.wordpress.org\/SergeyBiryukov\">@SergeyBiryukov<\/a>).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The release would not have been possible without the contributions of the following people. Their asynchronous coordination to deliver several fixes into a stable release is a testament to the power and capability of the WordPress community.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/profiles.wordpress.org\/audrasjb\">@audrasjb<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/costdev\">@costdev<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/cu121\">@cu121<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/dd32\">@dd32<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/davidbaumwald\">@davidbaumwald<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/ehtis\">@ehtis<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/johnbillion\">@johnbillion<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/johnjamesjacoby\">@johnjamesjacoby<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/martinkrcho\">@martinkrcho<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/matveb\">@matveb<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/oztaser\">@oztaser<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/paulkevan\">@paulkevan<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/peterwilsoncc\">@peterwilsoncc<\/a>,<a href=\"https:\/\/profiles.wordpress.org\/ravipatel\">@ravipatel<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/SergeyBiryukov\">@SergeyBiryukov<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/talldanwp\">@talldanwp<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/timothyblynjacobs\">@timothyblynjacobs<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/tykoted\">@tykoted<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/voldemortensen\">@voldemortensen<\/a>,&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/vortfu\">@vortfu<\/a>, and&nbsp;<a href=\"https:\/\/profiles.wordpress.org\/xknown\">@xknown<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"list-of-updated-packages\">List of updated packages<\/h2>\n\n\n\n<pre class=\"wp-block-preformatted\">COMING SOON\u2026<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"list-of-files-revised\">List of Files Revised<\/h2>\n\n\n\n<pre class=\"wp-block-preformatted\">COMING SOON\u2026<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>On October 17, 2022, WordPress 5.8.5 was released to the public. Installation\/Update Information To get this version, update automatically from the Dashboard &gt; Updates menu in your site&#8217;s admin area or visit https:\/\/wordpress.org\/download\/release-archive\/. For step-by-step instructions on installing and updating WordPress: If you are new to WordPress, we recommend that you begin with the following: [&hellip;]<\/p>\n","protected":false},"author":8670591,"featured_media":0,"menu_order":0,"template":"","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false},"helphub_major_release":[69],"class_list":["post-16106607","helphub_version","type-helphub_version","status-publish","hentry","helphub_major_release-5-8"],"revision_note":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16106607","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions"}],"about":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/types\/helphub_version"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/users\/8670591"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16106607\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/media?parent=16106607"}],"wp:term":[{"taxonomy":"helphub_major_release","embeddable":true,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/helphub_major_release?post=16106607"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}