Subject: CVS commit: pkgsrc/www/wordpress
From: John Klos
Date: 2017-05-30 09:20:15
Message id: 20170530072015.F01A7FBEE@cvs.NetBSD.org

Log Message:
Security update 4.7.5. Bugs fixed:

Insufficient redirect validation in the HTTP class. Reported by Ronni
Skansing.
Improper handling of post meta data values in the XML-RPC API. Reported by
Sam Thomas.
Lack of capability checks for post meta data in the XML-RPC API. Reported
by Ben Bidner of the WordPress Security Team.
A Cross Site Request Forgery (CSRF)  vulnerability was discovered in the
filesystem credentials dialog. Reported by Yorick Koster.
A cross-site scripting (XSS) vulnerability was discovered when attempting
to upload very large files. Reported by Ronni Skansing.
A cross-site scripting (XSS) vulnerability was discovered related to the
Customizer. Reported by Weston Ruter of the WordPress Security Team.

Files:
RevisionActionfile
1.68modifypkgsrc/www/wordpress/Makefile
1.54modifypkgsrc/www/wordpress/distinfo