{"id":16367131,"date":"2026-03-11T15:34:27","date_gmt":"2026-03-11T15:34:27","guid":{"rendered":"https:\/\/wordpress.org\/documentation\/?post_type=helphub_version&#038;p=16367131"},"modified":"2026-03-11T15:44:56","modified_gmt":"2026-03-11T15:44:56","slug":"version-6-9-4","status":"publish","type":"helphub_version","link":"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-9-4\/","title":{"rendered":"Version 6.9.4"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On March 11, 2026, WordPress 6.9.4 was released to the public. This is a security release that includes additional fixes that were not fully applied to the earlier <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-9-2\/\">6.9.2 security release<\/a> and <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-6-9-3\/\">6.9.3 bug fix release<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because this is a security release,<strong>&nbsp;it is recommended that you update your sites immediately<\/strong>.<\/p>\n\n\n\n<h2 id=\"installation-update-information\" class=\"wp-block-heading\">Installation\/Update Information<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To get this version, update automatically from the Dashboard &gt; Updates menu in your site\u2019s admin area or visit&nbsp;<a href=\"https:\/\/wordpress.org\/download\/release-archive\/\">https:\/\/wordpress.org\/download\/release-archive\/<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For step-by-step instructions on installing and updating WordPress:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/wordpress.org\/documentation\/article\/updating-wordpress\/\">Updating WordPress<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you are new to WordPress, we recommend that you begin with the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/wordpress.org\/support\/article\/new_to_wordpress_-_where_to_start\/\">New To WordPress \u2013 Where to Start<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/support\/article\/first-steps-with-wordpress\/\">First Steps With WordPress<\/a>&nbsp;or&nbsp;<a href=\"https:\/\/wordpress.org\/documentation\/article\/upgrading-wordpress-extended-instructions\/\">Upgrading WordPress Extended<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/support\/article\/wordpress-lessons\/\">WordPress Lessons<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Summary<\/h2>\n\n\n\n<h3 id=\"maintenance-updates\" class=\"wp-block-heading\">Security updates<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This release features several security fixes that were not fully applied to the 6.9.2 release. Because this is a security release, <strong>it is recommended that you update your sites immediately.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The security team would like to thank the following people for <a href=\"https:\/\/hackerone.com\/wordpress?type=team\">responsibly reporting vulnerabilities<\/a>, and allowing them to be fixed in this release:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A PclZip path traversal issue reported independently by <a href=\"https:\/\/profiles.wordpress.org\/francescocarlucci\/\">Francesco Carlucci<\/a> and <a href=\"https:\/\/profiles.wordpress.org\/kaminuma\/\">kaminuma<\/a><\/li>\n\n\n\n<li>An authorization bypass on the Notes feature reported by <a href=\"https:\/\/profiles.wordpress.org\/kaminuma\/\">kaminuma<\/a><\/li>\n\n\n\n<li>An XXE in the external getID3 library reported by <a href=\"https:\/\/profiles.wordpress.org\/regex33\/\">Youssef Achtatal<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/profiles.wordpress.org\/kraftner\">Thomas Kr\u00e4ftner<\/a>\u00a0for his responsible disclosure<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The WordPress security team have worked with the maintainer of the external getID3 library, James Heinrich, to coordinate a fix to getID3. A new version of getID3 <a href=\"https:\/\/github.com\/JamesHeinrich\/getID3\/releases\">is available here<\/a>.<\/p>\n\n\n\n<h2 id=\"changelog\" class=\"wp-block-heading\">Change log<\/h2>\n\n\n\n<h3 id=\"list-of-files-revised\" class=\"wp-block-heading\">List of files revised<\/h3>\n\n\n\n<pre class=\"wp-block-preformatted\">\/wp-admin\/includes\/file.php<br>\/wp-includes\/ID3\/getid3.lib.php<br>\/wp-includes\/rest-api\/endpoints\/class-wp-rest-comments-controller.php<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">List of packages revised<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No package was revised.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On March 11, 2026, WordPress 6.9.4 was released to the public. This is a security release that includes additional fixes that were not fully applied to the earlier 6.9.2 security release and 6.9.3 bug fix release. Because this is a security release,&nbsp;it is recommended that you update your sites immediately. Installation\/Update Information To get this [&hellip;]<\/p>\n","protected":false},"author":42547,"featured_media":0,"menu_order":0,"template":"","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false},"helphub_major_release":[104],"class_list":["post-16367131","helphub_version","type-helphub_version","status-publish","hentry","helphub_major_release-6-9"],"revision_note":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16367131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions"}],"about":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/types\/helphub_version"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/users\/42547"}],"version-history":[{"count":5,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16367131\/revisions"}],"predecessor-version":[{"id":16367141,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/wordpress-versions\/16367131\/revisions\/16367141"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/media?parent=16367131"}],"wp:term":[{"taxonomy":"helphub_major_release","embeddable":true,"href":"https:\/\/wordpress.org\/documentation\/wp-json\/wp\/v2\/helphub_major_release?post=16367131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}