WordPress x Lightspeed – updated to 5.4.2

As per our best practice, this release has been automatically updated for WordPress x Lightspeed customers. Self-managed customers are strongly encouraged to upgrade to this version. Please be advised that as of today, June 15 2020, the WordPress containers that are Managed by Lightspeed have all been upgraded from version WordPress 5.4.1. to version 5.4.2. We have retired WordPress 5.4.1. series across all customers.


For Self-Managed customers, go to Dashboard → Updates and click Update Now.

Security Updates:

WordPress versions 5.4 and earlier are affected by the following bugs, which are fixed in version 5.4.2. If you haven’t yet updated to 5.4, there are also updated versions of 5.3 and earlier that fix the security issues.

  • Props to Sam Thomas (jazzy2fives) for finding an XSS issue where authenticated users with low privileges are able to add JavaScript to posts in the block editor.
  • Props to Luigi – (gubello.me) for discovering an XSS issue where authenticated users with upload permissions are able to add JavaScript to media files.
  • Props to Ben Bidner of the WordPress Security Team for finding an open redirect issue in wp_validate_redirect().
  • Props to Nrimo Ing Pandum for finding an authenticated XSS issue via theme uploads.
  • Props to Simon Scannell of RIPS Technologies for finding an issue where set-screen-option can be misused by plugins leading to privilege escalation.
  • Props to Carolina Nymark for discovering an issue where comments from password-protected posts and pages could be displayed under certain conditions.

Shopping Cart