The WordPress development team released on Thursday the version 5.0.1 of the popular CMS, that addresses several flaws. Researcher Tim Coen discovered several cross-site scripting (XSS) vulnerabilities in the CMS. One of the flaws is caused by the ability of contributors to edit new comments from users with higher privileges. Another flaw discovered by experts at Yoast affects some uncommon configurations and causes the user activation screen being indexed by search engines. Security updates that addressed the above flaws have been released for WordPress 4.9 and older releases.”]
Source: https://securityaffairs.co/wordpress/78906/security/wordpress-5_0_1.html

