WordPress versions 3.9.2 and earlier are affected by a critical cross-site scripting vulnerability, which could enable anonymous users to compromise a site. This was reported by Jouko Pynnonen. This issue does not affect version 4.0, but version 4.0.1 does address these eight security issues...
Most of my sites I have set to update wordpress automatically, but I always wonder whether that might be a problem in itself if the plugins are incompatible with the update.
lorax
12:21 am on Nov 22, 2014 (gmt 0)
If your plugins are in the WordPress repository and reasonably current then you are unlikely to see an issue. Of course YMMV with too many plugins, custom coding, etc...
Planet13
1:15 am on Nov 22, 2014 (gmt 0)
Good to know that most recent plugins will survive the automatic updates.
[edited by: lorax at 3:07 am (utc) on Nov 22, 2014] [edit reason] snipped editing discussion [/edit]
ergophobe
3:54 pm on Nov 22, 2014 (gmt 0)
After my last Drupal experience, I'm basically changing everything to auto-update.
The thing is, what would you rather have
A) An update that breaks your site which, if you have a service like Pingdom active, will alert you in minutes and you can fix a 100% known and understood code problem
B) An update that you don't get to because you don't have a 24/7 IT department and sometimes you're busy and by the time you get to it, the entire server needs to be stripped down, the entire VM erased and all server config and sites rebuilt.
I'm finding option A more acceptable than I did in the past.
Planet13
9:11 pm on Nov 22, 2014 (gmt 0)
Thanks for the input, ergophobe.
Yeah, Option A does sound a bit better...
Aleksandr 85
8:52 am on Dec 4, 2014 (gmt 0)
Thanks for the information!
herbie9
7:30 am on Dec 18, 2014 (gmt 0)
Does anyone know when WP 4.1 will be released? I heard it was supposed to be 16 Dec, but it is 18 Dec already and nothing new yet.
hannahwr
10:15 am on Dec 18, 2014 (gmt 0)
I got the notice to check my plugins to be ready with WP 4.1 so I think they will release it soon