WordPress 4.7.3 has been released on 6th March 20017. This is a security release for all previous versions and WordPress core team strongly advised to update immediately.
WordPress versions 4.7.3 fixes the following six security issues:
- Cross-site scripting (XSS) via media file metadata.
- Control characters can trick redirect URL validation.
- Unintended files can be deleted by administrators using the plugin deletion functionality.
- Cross-site scripting (XSS) via video URL in YouTube embeds.
- Cross-site scripting (XSS) via taxonomy term names.
- Cross-site request forgery (CSRF) in Press This leading to excessive use of server resources.
WordPress 4.7.3 also contains 39 maintenance fixes to fix a range of non-security related issues.