Security component

If you have encountered a security issuesecurity issue A security issue is a type of bug that can affect the security of WordPress installations. Specifically, it is a report of a bug that you have found in the WordPress core code, and that you have determined can be used to gain some level of access to a site running WordPress that you should not have. that isn’t addressed in a released version of WordPress, please report it to the WordPress HackerOne program. For more, see our Security FAQ in the handbook.

Recent posts on the make/coreCore Core is the set of software required to run WordPress. The Core Development Team builds WordPress. blogblog (versus network, site)

View all posts tagged security.

55 open tickets in the Security component

55 open tickets defect (bug) enhancement feature request task (blessed)
5.9 1 2 0 0
Awaiting Review 14 18 3 0
Future Release 5 8 3 1

55 open tickets. Last 7 days: +2 tickets

7 tickets that have no replies

View list on Trac

  • #43215  Allow wp_kses to pass allowed CSSCSS Cascading Style Sheets. properties
  • #51159  Let's expand our context specific escaping methods for wp_json_encode(). javascriptJavaScript JavaScript or JS is an object-oriented computer programming language commonly used to create interactive effects within web browsers. WordPress makes extensive use of JS for a better user experience. While PHP is executed on the server, JS executes within a user’s browser. https://www.javascript.com/. template coding-standards
  • #51611  Escape echoing Core functions
  • #52333  Lack of the : entity on the list of allowed entity names in kses.php
  • #52388  Use HTTPSHTTPS HTTPS is an acronym for Hyper Text Transfer Protocol Secure. HTTPS is the secure version of HTTP, the protocol over which data is sent between your browser and the website that you are connected to. The 'S' at the end of HTTPS stands for 'Secure'. It means all communications between your browser and the website are encrypted. This is especially helpful for protecting sensitive data like banking information. URLURL A specific web address of a website or web page on the Internet, such as a website’s URL www.wordpress.org already during installation if supported
  • #53296  Do trim $hook_name within add_action() and add_filter() function
  • #53869  Post type / TaxonomyTaxonomy A taxonomy is a way to group things together. In WordPress, some common taxonomies are category, link, tag, or post format. https://codex.wordpress.org/Taxonomies#Default_Taxonomies. Label Hardening: Prevent Raw HTMLHTML HyperText Markup Language. The semantic scripting language primarily used for outputting content in web browsers. tags in output / Media Library eval of HTML entities in label

3 tickets slated for 5.9

View list in Trac

  • #51407  Remove inline event handlers and JavaScript URIs for Strict CSP-compatibility javascript
  • #51438  Use CSP directive upgrade-insecure-requests when using HTTPS
  • #53597  Correct the documentation for the `wp_kses_allowed_html` filterFilter Filters are one of the two types of Hooks https://codex.wordpress.org/Plugin_API/Hooks. They provide a way for functions to modify data of other functions. They are the counterpart to Actions. Unlike Actions, filters are meant to work in an isolated manner, and should never have side effects such as affecting global variables and output. docs

55 open tickets

Open enhancements: 28 View list on Trac
Open tasks: 1 View list on Trac
Open feature requests: 6 View list on Trac

Help maintain this component

Component maintainers:

Many contributors help maintain one or more components. These maintainers are vital to keeping WordPress development running as smoothly as possible. They triagetriage The act of evaluating and sorting bug reports, in order to decide priority, severity, and other factors. new tickets, look after existing ones, spearhead or mentor tasks, pitch new ideas, curate roadmaps, and provide feedback to other contributors. Longtime maintainers with a deep understanding of particular areas of core are always seeking to mentor others to impart their knowledge.

Want to help? Start following this component! Adjust your notifications here. Feel free to dig into any ticketticket Created for both bug reports and feature development on the bug tracker..

Contributors following this component: