WordPress Cluster 9.0.89

  • Plugin updates
    • Ad-inserter 2.6.8
    • Advanced-custom-fields-pro 5.8.9
    • Amp 1.5.3
    • Category-posts 4.9.4
    • Custom-post-type-permalinks 3.3.5
    • Mailchimp-for-wp 4.7.7
    • Pods 2.7.20
    • Redis-cache 1.5.7
    • Wp-pagenavi 2.93.3
  • PR
    • https://github.com/dc-thomson/wordpress/pull/2672
    • https://github.com/dc-thomson/wordpress/pull/2674
    • https://github.com/dc-thomson/wordpress/pull/2675
    • https://github.com/dc-thomson/wordpress/pull/2676
    • https://github.com/dc-thomson/wordpress/pull/2677
    • https://github.com/dc-thomson/wordpress/pull/2679
    • https://github.com/dc-thomson/wordpress/pull/2681
    • https://github.com/dc-thomson/wordpress/pull/2682
    • https://github.com/dc-thomson/wordpress/pull/2683

WordPress Cluster 9.0.88

  • Network UI cleanup
    • removed adcompass and the code
    • removed audscience and the code
    • removed gigya, code already removed as part of Zephr
  • PR
    • https://github.com/dc-thomson/wordpress/pull/2657

WordPress Cluster 9.0.87 – Security Update

  • WordPress 5.4.1
    • https://wordpress.org/support/wordpress-version/version-5-4-1/
      • Six security issues affect WordPress versions 5.4 and earlier; version 5.4.1 fixes them, so you’ll want to upgrade. If you haven’t yet updated to 5.4, there are also updated versions of 5.3 and earlier that fix the security issues.
        • Props to Muaz Bin Abdus Sattar and Jannes who both independently reported an issue where password reset tokens were not properly invalidated
        • Props to ka1n4t for finding an issue where certain private posts can be viewed unauthenticated
        • Props to Evan Ricafort for discovering an XSS issue in the Customizer
        • Props to Ben Bidner from the WordPress Security Team who discovered an XSS issue in the search block
        • Props to Nick Daugherty from WPVIP.com / WordPress Security Team who discovered an XSS issue in wp-object-cache
        • Props to Ronnie Goodrich (Kahoots) and Jason Medeiros who independently reported an XSS issue in file uploads.
        • Additionally, an authenticated XSS issue in the block editor was discovered by Nguyen the Duc in WordPress 5.4 RC1 and RC2. It was fixed in 5.4 RC5. We wanted to be sure to give credit and thank them for all of their work in making WordPress more secure.
  • PR
    • https://github.com/dc-thomson/wordpress/pull/2684

WordPress Cluster 9.0.84

  • Plugin updates
      • WordFence 7.4.7
      • WordPress SEO 14.0
      • WordPress SEO Premium 14.0
      • WP All Import Pro 4.6.0
        • WP All Import – ACF Add-On 3.2.5
    • PR
      • https://github.com/dc-thomson/wordpress/pull/2667
      • https://github.com/dc-thomson/wordpress/pull/2668
      • https://github.com/dc-thomson/wordpress/pull/2669
      • https://github.com/dc-thomson/wordpress/pull/2670
    • ROLLED BACK Plugins that resulted in outage:
      • Ad-inserter 2.6.8
      • Advanced-custom-fields-pro 5.8.9
      • Amp 1.5.3
      • Category-posts 4.9.4
      • Custom-post-type-permalinks 3.3.5
      • Mailchimp-for-wp 4.7.7
      • Pods 2.7.20
      • Redis-cache 1.5.7
      • Wp-pagenavi 2.93.3

WordPress Cluster 9.0.83

  • MU Plugins
    • WaveFM Listen Live
      • Removed
    • DCT Media Listen Live 1.0.0
      • Shortcode and widget for displaying DCT Media radio stations on WP sites.

PR: https://github.com/dc-thomson/wordpress/pull/2666

WordPress Cluster 9.0.82

  • Plugins updated:
    • DCT CTAs 1.1.0
      • Added Subscribe CTA ID field to Category edit screen
  • Themes updated:
    • Blocks 2.8.0
      • Refactored Simple template’s Subscribe CTA (previously hardcoded) to work with Subscribe CTA ID field
      • General CSS fixes

PR: https://github.com/dc-thomson/wordpress/pull/2660

WordPress Cluster 9.0.80

  • Plugins updated:
    • Blaize 1.12.0
      • Added group attribute to [blaize-subscriptions] shortcode for rendering custom subscription package groups
      • Amendments to [blaize-payment] shortcode template
      • ACF PHP streamlining
      • JS improvements
      • CSS improvements
  • VVV
    • Changes to readme.md
    • Some configuration refinements
    • Provisions correctly on MacOS hosts

PR: https://github.com/dc-thomson/wordpress/pull/2650, https://github.com/dc-thomson/wordpress/pull/2651