{"id":222341,"date":"2019-09-05T10:21:09","date_gmt":"2019-09-05T08:21:09","guid":{"rendered":"https:\/\/www.borncity.com\/blog\/?p=222341"},"modified":"2020-09-23T07:44:36","modified_gmt":"2020-09-23T05:44:36","slug":"wordpress-5-2-3","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2019\/09\/05\/wordpress-5-2-3\/","title":{"rendered":"WordPress 5.2.3"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2014\/07\/wp_thumb.jpg\" alt=\"\" width=\"64\" height=\"64\" \/>[<a href=\"https:\/\/borncity.com\/win\/2019\/09\/05\/wordpress-5-2-3\/\" target=\"_blank\" rel=\"noopener noreferrer\">English<\/a>]Die Entwickler haben die Nacht ein Update f\u00fcr WordPress freigegeben, welches das CMS auf die Version 5.2.3 hebt. Durch das Update auf die Version 5.2.3 werden Sicherheitsprobleme und 29 Fehler behoben.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg08.met.vgwort.de\/na\/563ba9ec52f6439eb5ac1e99eda84508\" alt=\"\" width=\"1\" height=\"1\" \/>Hier ein \u00dcberblick, was in WordPress 5.2.3 so alles an Problemen und Schwachstellen beseitigt wurde<\/p>\n<h2>Sicherheitsfixes<\/h2>\n<p>Gem\u00e4\u00df <a href=\"https:\/\/wordpress.org\/news\/2019\/09\/wordpress-5-2-3-security-and-maintenance-release\/\" target=\"_blank\" rel=\"noopener noreferrer\">dieser Support-Seite<\/a> wurden in WordPress 5.2.3 die nachfolgenden Sicherheitsfixes vorgenommen;<\/p>\n<ul>\n<li>Props to <a href=\"https:\/\/blog.ripstech.com\/authors\/simon-scannell\/\" target=\"_blank\" rel=\"noopener noreferrer\">Simon Scannell of RIPS Technologies<\/a> for finding and disclosing two issues. The first, a cross-site scripting (XSS) vulnerability found in post previews by contributors. The second was a cross-site scripting vulnerability in stored comments.<\/li>\n<li>Props to Tim Coen for disclosing an issue where validation and sanitization of a URL could lead to an open redirect.<\/li>\n<li>Props to Anshul Jain for disclosing reflected cross-site scripting during media uploads.<\/li>\n<li>Props to <a href=\"https:\/\/fortiguard.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Zhouyuan Yang of Fortinet's FortiGuard Labs<\/a> who disclosed a vulnerability for cross-site scripting (XSS) in shortcode previews.<\/li>\n<li>Props to Ian Dunn of the Core Security Team for finding and disclosing a case where reflected cross-site scripting could be found in the dashboard.<\/li>\n<li>Props to Soroush Dalili (<a href=\"https:\/\/twitter.com\/irsdl?lang=en\" target=\"_blank\" rel=\"noopener noreferrer\">@irsdl<\/a>) from NCC Group for disclosing an issue with URL sanitization that can lead to cross-site scripting (XSS) attacks.<\/li>\n<li>In addition to the above changes, we are also updating jQuery on older versions of WordPress. This change was <a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47020\" target=\"_blank\" rel=\"noopener noreferrer\">added in 5.2.1<\/a> and is now being brought to older versions.<\/li>\n<\/ul>\n<h2>Fehlerbehebungen<\/h2>\n<p>Gem\u00e4\u00df den WordPress-Entwicklern wurden die nachfolgenden Bug-Fixes vorgenommen \u2013 weitere Informationen finden sich in den <a href=\"https:\/\/wordpress.org\/support\/wordpress-version\/version-5-2-3\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ver\u00f6ffentlichungsmitteilungen<\/a>.<\/p>\n<ul>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/38415\" target=\"_blank\" rel=\"noopener noreferrer\">#38415<\/a>: New Custom Link menu item has a wrong fallback label<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/45739\" target=\"_blank\" rel=\"noopener noreferrer\">#45739<\/a>: Block Editor: $editor_styles bug.<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/45935\" target=\"_blank\" rel=\"noopener noreferrer\">#45935<\/a>: A URL in do_block_editor_incompatible_meta_box function does not have classic-editor__forget parameter<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/46757\" target=\"_blank\" rel=\"noopener noreferrer\">#46757<\/a>: Media Trash: The Bulk Media options when in the Trash shouldn't provide two primary buttons<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/46758\" target=\"_blank\" rel=\"noopener noreferrer\">#46758<\/a>: Media Trash: Primary button(s) should be on the left<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/46899\" target=\"_blank\" rel=\"noopener noreferrer\">#46899<\/a>: Ensure that tables generated by the Settings API have no semantics<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47079\" target=\"_blank\" rel=\"noopener noreferrer\">#47079<\/a>: Incorrect version for excerpt_allowed_blocks filter<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47113\" target=\"_blank\" rel=\"noopener noreferrer\">#47113<\/a>: Media views: dismiss notice button is invisible<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47145\" target=\"_blank\" rel=\"noopener noreferrer\">#47145<\/a>: Feature Image dialog does not follow the dialog pattern<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47190\" target=\"_blank\" rel=\"noopener noreferrer\">#47190<\/a>: Twenty Seventeen: Native audio and video embeds have no focus state.<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47340\" target=\"_blank\" rel=\"noopener noreferrer\">#47340<\/a>: Twenty Nineteen: Revise Latest Posts block styles to support post content options.<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47386\" target=\"_blank\" rel=\"noopener noreferrer\">#47386<\/a>: Fix headings hierarchy in the legacy Custom Background and Custom Header pages<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47390\" target=\"_blank\" rel=\"noopener noreferrer\">#47390<\/a>: Improve accessibility of forms elements within some \"form-table\" forms<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47414\" target=\"_blank\" rel=\"noopener noreferrer\">#47414<\/a>: Twenty Seventeen: Button block preview has extra spacing within button<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47458\" target=\"_blank\" rel=\"noopener noreferrer\">#47458<\/a>: Fix tab sequence order in the Media attachment browser<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47489\" target=\"_blank\" rel=\"noopener noreferrer\">#47489<\/a>: Emoji are substituted in preformatted blocks<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47502\" target=\"_blank\" rel=\"noopener noreferrer\">#47502<\/a>: Media modal bottom toolbar cuts-off content in Internet Explorer 11<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47538\" target=\"_blank\" rel=\"noopener noreferrer\">#47538<\/a>: Minor Verbiage Update \u2013 Switch 'developer time' for 'a developer'<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47543\" target=\"_blank\" rel=\"noopener noreferrer\">#47543<\/a>: Twenty Seventeen: buttons don't change color on hover and focus<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47561\" target=\"_blank\" rel=\"noopener noreferrer\">#47561<\/a>: Plugin: View details popup layout issue<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47603\" target=\"_blank\" rel=\"noopener noreferrer\">#47603<\/a>: My account toggle on admin bar not visible at high zoom levels<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47604\" target=\"_blank\" rel=\"noopener noreferrer\">#47604<\/a>: Undefined variable: locked in wp-admin\/edit-form-blocks.php<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47687\" target=\"_blank\" rel=\"noopener noreferrer\">#47687<\/a>: Use alt tags for gallery images in editor<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47688\" target=\"_blank\" rel=\"noopener noreferrer\">#47688<\/a>: Color hex code in color picker displayed in RTL instead of LTR on RTL install (take 2)<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47693\" target=\"_blank\" rel=\"noopener noreferrer\">#47693<\/a>: customizer Color picker should get closed when click on color picker area.<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47723\" target=\"_blank\" rel=\"noopener noreferrer\">#47723<\/a>: Adding a custom link in nav-menus.php doesn't trim whitespace<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47758\" target=\"_blank\" rel=\"noopener noreferrer\">#47758<\/a>: Font sizes on installation screen are too small<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47835\" target=\"_blank\" rel=\"noopener noreferrer\">#47835<\/a>: PHP requirement always set to null for plugins<\/li>\n<li><a href=\"https:\/\/core.trac.wordpress.org\/ticket\/47888\" target=\"_blank\" rel=\"noopener noreferrer\">#47888<\/a>: Adding a custom link in menu via Customize doesn't trim whitespace.<\/li>\n<\/ul>\n<p>Der IT-Blog wurde die Nacht automatisch auf die neuen WordPress-Version aktualisiert. Eine Multi-Site-Installation mit diversen anderen Blogs (englischer IT-Blog, Reisen, Senioren, eScooter etc.) habe ich heute morgen ohne Probleme auf die neue Version aktualisieren k\u00f6nnen. Allerdings zeigt mir das Sicherheits-Add-In WordFence noch an, dass ein Update auf WordPress 5.2.3 anst\u00fcnde &#8211; sollte aber nach einigen Stunden verschwinden (war bei den letzten Updates auch so).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[English]Die Entwickler haben die Nacht ein Update f\u00fcr WordPress freigegeben, welches das CMS auf die Version 5.2.3 hebt. Durch das Update auf die Version 5.2.3 werden Sicherheitsprobleme und 29 Fehler behoben.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7459,185,1574],"tags":[4315,4349],"class_list":["post-222341","post","type-post","status-publish","format-standard","hentry","category-software","category-update","category-wordpress","tag-update","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/222341","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=222341"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/222341\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=222341"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=222341"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=222341"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}