If you are a WordPress User, it is very important that your WordPress installation has been updated today! This is a security release for all versions and we strongly encourage you to update your sites immediately!
WordPress versions 4.4.1 and earlier are affected by two security issues: a server-side request forgery (SSRF) for certain local URIs, reported by Ronni Skansing; and an open redirection attack, reported by Shailesh Suthar, under the responsible disclosure system. Both have now patched and secured in V4.4.2
The Open Redirection Attack lets an attacker send a user to a WordPress site using a URL that contains a parameter that redirects them to another site. It’s a useful way of performing phishing attacks whereby an attacker sends a victim to a malicious site by disguising the link as a non-malicious site or a known site.

In addition to the security issues above, WordPress 4.4.2 fixes the following 17 bugs from 4.4 and 4.4.1.
- #35356 wp_list_comments ignores $comments parameter
- #35478 4.4 Regression on Querying for Comments by Multiple Post Fields
- #35192 Comments_clauses filter
- #35251 ‘networks’ should be global cache group
- #35316 Images with latin extended characters in exif (slovak/czech) are missing thumbnails
- #35327 Using libsodium for random bytes breaks plugin update in WP 4.4
- #35344 Strange pagination issue on front page after 4.4.1 update
- #35355 Customizer should not try to return to the login screen
- #35361 Error in SQL syntax search page
- #35376 Default URL for emoji images should be always https
- #35378 Incorrect comment ordering when comment threading is turned off
- #35401 Taxonomies Quick Edit: prevent page reload when submitting
- #35402 per_page parameter no longer works in wp_list_comments
- #35412 ModSecurity2 blocks Potential Obfuscated Javascript in outbound anomaly
- #35419 Incorrect comment pagination when comment threading is turned off
- #35462 update_term_cache and deleting object_id
- #35447 Button to delete inactive widgets is displayed on inactive sidebars
All InstaHost clients who had their WordPress sites installed by our InstaSupport Team have already been automatically updated by our team.
WARNING: The upgrade process will affect all files and folders included in the main WordPress installation. This includes all the core files used to run WordPress. If you have made any modifications to those files, your changes will be lost.
Before you get started, it’s a good idea to backup your website. This means if there are any issues you can restore your website.
Most sites are now able to automatically apply these updates in the background. If your site is capable of one-click updates without entering FTP credentials, then your site should be able to update from 3.7.
You can launch the update by clicking the link in the new version banner (if it’s there) or by going to the Dashboard > Updates screen. Once you are on the “Update WordPress” page, click the button “Update Now” to start the process off. You shouldn’t need to do anything else and, once it’s finished, you will be up-to-date.
One-click updates work on most servers. If you have any problems, it is probably related to permissions issues on the filesystem.
If you see a “failed update” nag message, delete the file .maintenance from your WordPress directory using FTP. This will remove the “failed update” nag message.
If the one-click upgrade doesn’t work for you, don’t panic! Just try a manual update, please contact InstaSupport for help on manual updates.








