Releases: roots/wordpress
Version 5.2.20
Version notes available on WordPress.org Documentation.
Version 5.1.18
Version notes available on WordPress.org Documentation.
Version 5.0.21
Version notes available on WordPress.org Documentation.
Version 4.9.25
Version notes available on WordPress.org Documentation.
Version 4.8.24
Version notes available on WordPress.org Documentation.
Version 6.4.2
Version notes available on WordPress.org Documentation.
Version 6.4.1
Version notes available on WordPress.org Documentation.
Version 6.4
Sourced from WordPress.org Documentation.
Highlights
This latest version of WordPress introduces a new, versatile default theme and a suite of upgrades to empower every step of your creative journey. Craft your content seamlessly with further writing improvements. Explore more ways to bring your vision to life and streamline site editing with enhanced tools. Whether you’re new to WordPress or an experienced creator, WordPress 6.4 has something for you. Discover the unmatched flexibility of building with blocks and let your ideas take flight.
Meet Twenty Twenty-Four
Experience site editing at its finest with Twenty Twenty-Four. This new multi-faceted default theme has been thoughtfully crafted with three distinct use cases in mind, from writers and artists to entrepreneurs. Save time and effort with its extensive collection of over 35 templates and patterns—and unlock a world of creative possibilities with a few tweaks. Twenty Twenty-Four’s remarkable flexibility ensures an ideal fit for almost any type of site. Check it out in this demo.
Let your writing flow
New enhancements ensure your content creation journey is smooth. Find new keyboard shortcuts in List View, smarter list merging, and enhanced control over link settings. A cohesive toolbar experience for the Navigation, List, and Quote blocks lets you work efficiently with the tooling options you need.
The Command Palette just got better
First introduced in WordPress 6.3, the Command Palette is a powerful tool to quickly find what you need, perform tasks efficiently, and speed up your building workflow. Enjoy a refreshed design and new commands to perform block-specific actions in this release.
Categorize and filter patterns
Patterns are an excellent way to leverage the potential of blocks and simplify your site-building process. WordPress 6.4 allows you to organize them with custom categories. Plus, new advanced filtering in the Patterns section of the inserter makes finding all your patterns more intuitive.
Get creative with more design tools
Build beautiful and functional layouts with an expanded set of design tools. Play with background images in Group blocks for unique designs and maintain image dimensions consistent with placeholder aspect ratios. Do you want to add buttons to your Navigation block? Now you can do it conveniently without a line of code.
Make your images stand out
Enable lightbox functionality to let your site visitors enjoy full-screen, interactive images on click. Apply it globally or to specific images to customize the viewing experience.
Rename Group blocks
Set custom names for Group blocks to organize and distinguish areas of your content easily. These names will be visible in List View.
Preview images in List View
New previews for Gallery and Image blocks in List View let you visualize and locate where images on your content are at a glance.
Share patterns across sites
Need to use your custom patterns on another site? Import and export them as JSON files from the Site Editor’s patterns view.
Introducing Block Hooks
Block Hooks enables developers to automatically insert dynamic blocks at specific content locations, enriching the extensibility of block themes through plugins. While considered a developer tool, this feature is geared to respect your preferences and gives you complete control to add, dismiss, and customize auto-inserted blocks to your needs.
Performance wins
This release includes more than 100 performance-related updates for a faster and more efficient experience. Notable enhancements focus on template loading performance for themes (including Twenty Twenty-Four), usage of the script loading strategies “defer” and “async” in core, blocks, and themes, and optimization of autoloaded options.
Accessibility highlights
Every release is committed to making WordPress accessible to everyone. WordPress 6.4 brings several List View improvements and aria-label support for the Navigation block, among other highlights. The admin user interface includes enhancements to button placements, “Add New” menu items context, and Site Health spoken messages. Learn more about all the work aimed at improving accessibility in this post.
Other notes of interest
- PHP 8.1 or 8.2 are recommended for use with WordPress 6.4. Find in-depth details on PHP support in this post.
- WordPress 6.4 disables attachment pages for new installations.
Version 6.3.2
Sourced from WordPress.org Documentation.
Summary
Maintenance updates
This security and maintenance release features 19 bug fixes on Core, 22 bug fixes for the Block Editor, and 8 security fixes.
This is a short-cycle release. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.
Security updates
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
- Marc Montpas of Automattic for finding a potential disclosure of user email addresses.
- Marc Montpas of Automattic for finding an RCE POP Chains vulnerability.
- Rafie Muhammad and Edouard L of Patchstack along with a WordPress commissioned third-party audit for each independently identifying a XSS issue in the post link navigation block.
- Jb Audras of the WordPress Security Team and Rafie Muhammad of Patchstack for each independently discovering an issue where comments on private posts could be leaked to other users.
- James Golovich and WhiteCyberSec for each independently identifying a way for logged in user to execute any shortcode.
- mascara7784 for identifying a XSS vulnerability in the application password screen.
- Jorge Costa of the WordPress Core Team for identifying XSS vulnerability in the footnotes block.
- s5s and raouf_maklouf for independently identifying a cache poisoning DoS vulnerability.
Version 6.2.3
Sourced from WordPress.org Documentation.
Summary
This is a short-cycle release. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.
Security updates
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
- Marc Montpas of Automattic for finding a potential disclosure of user email addresses.
- Marc Montpas of Automattic for finding an RCE POP Chains vulnerability.
- Rafie Muhammad and Edouard L of Patchstack along with a WordPress commissioned third-party audit for each independently identifying a XSS issue in the post link navigation block.
- Jb Audras of the WordPress Security Team and Rafie Muhammad of Patchstack for each independently discovering an issue where comments on private posts could be leaked to other users.
- James Golovich and WhiteCyberSec for each independently identifying a way for logged in user to execute any shortcode.
- mascara7784 for identifying a XSS vulnerability in the application password screen.
- Jorge Costa of the WordPress Core Team for identifying XSS vulnerability in the footnotes block.
- s5s and raouf_maklouf for independently identifying a cache poisoning DoS vulnerability.