WordPress 6.4.3: Vulnerability fixes and security improvements

Article image WordPress 6.4.3: Vulnerability fixes and security improvements
Article image WordPress 6.4.3: Vulnerability fixes and security improvements
Publication date:19.01.2026
Blog category: Web Technology News

The WordPress 6.4.3 update was released in response to two discovered vulnerabilities and also includes 21 bug fixes. The first patch addresses a vulnerability that allows PHP files to be downloaded via the plugin installer to be bypassed. This is a flaw in WordPress that allows attackers to download PHP files using the plugin and theme uploader. However, this vulnerability is not so terrible, since attackers need administrator rights to use it.

"The second patch addresses the way that options are stored - it first sanitizes them before checking the data type of the option - arrays and objects are serialized, as well as already serialized data, which is serialized again. While this already happens when options are updated, it was not performed during site installation, initialization, or upgrade."

🚀 The WordPress system, according to the fix, changes the way options are stored - first clears them, then checks the data type of the option - arrays and objects are serialized, as well as already serialized data being serialized again. Although this already happens when updating options, it was not done during installation, initialization or updating the site.

  • 📌 PHP File Upload Bypass and PHP Object Injection vulnerabilities have been fixed
  • 📌 The update also includes 21 bug fixes
  • 📌 WordPress recommends that you update your sites immediately
The update includes fixes for PHP File Upload Bypass and PHP Object Injection vulnerabilities, as well as 21 bug fixes.
Yes, WordPress recommends that you update your sites immediately.
🧩 Summary: The WordPress 6.4.3 security update includes fixes for two vulnerabilities and 21 bugs found in WordPress. This is an important update that all WordPress users should install.
🧠 Own considerations: In the world of web development, security is a key aspect. WordPress security is no exception. Regular security updates like WordPress 6.4.3 are essential to protect your websites from potential threats and ensure the best experience for your users.

Comments

ThreadKeeper Avatar
Покращення безпеки у WordPress завжди викликає велику увагу. Важливо, що розробники реагують на виявлені уразливості, навіть якщо ризики виглядають незначними. Регулярні оновлення допомагають підтримувати сайт у безпеці. Чи плануєте ви вже оновлення до нової версії?
19.01.2026 07:00 ThreadKeeper