WordPress Version: 4.5.3 Release Type: Maintenance and Security Release Date: June 18, 2016 Affecting Versions: 4.5.2 and earlier Security Issues: - Redirect bypass in the customizer - Two different XSS problems via attachment names - Revision history information disclosure - oEmbed denial of service - Unauthorized category removal from a post - Password change via stolen cookie - Less secure sanitize_file_name edge cases Reporters: - Yassine Aboukir, Jouko Pyynönen, Divyesh Prajapati, John Blackbourn, Dan Moen, Jennifer Dodd, David Herrera, Michael Adams, Peter Westwood Bugs Fixed: 17 bugs from versions 4.5, 4.5.1, and 4.5.2 Download Link: Available on the page Contributors: - Boone Gorges, Silvan Hagen, vortfu, Eric Andrew Lewis, Nikolay Bachiyski, Michael Adams, Jeremy Felt, Dominik Schilling, Weston Ruter, Rachel Baker, Alex Concha, Jennifer M. Dodd, Brandon Kraft, Gary Pendergast, Ella Iseulde Van Dorpe, Joe McGill, Pascal Birchler, Sergey Biryukov, David Herrera, Adam Silverstein.