January 30, 2017

Video: How to Add Title Attribute in WordPress Navigation Menus



WPBeginner - WordPress Tutorials originally appeared at http://www.youtube.com/watch?v=2OE5l0WgAbE

January 26, 2017

WordPress 4.7.2 Security Release

WordPress 4.7.2 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately.

WordPress versions 4.7.1 and earlier are affected by three security issues:

  1. The user interface for assigning taxonomy terms in Press This is shown to users who do not have permissions to use it. Reported by David Herrera of Alley Interactive.
  2. WP_Query is vulnerable to a SQL injection (SQLi) when passing unsafe data. WordPress core is not directly vulnerable to this issue, but we’ve added hardening to prevent plugins and themes from accidentally causing a vulnerability. Reported by Mo Jangda (batmoo).
  3. A cross-site scripting (XSS) vulnerability was discovered in the posts list table. Reported by Ian Dunn of the WordPress Security Team.

Thank you to the reporters of these issues for practicing responsible disclosure.

Download WordPress 4.7.2 or venture over to Dashboard → Updates and simply click “Update Now.” Sites that support automatic background updates are already beginning to update to WordPress 4.7.2.

Thanks to everyone who contributed to 4.7.2.



WordPress 4.7.2 Security Release was originally posted at https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/

January 23, 2017

Video: How to Create a Contact Form in WordPress



WPBeginner - WordPress Tutorials originally appeared at http://www.youtube.com/watch?v=OZ7oUUED9bg

January 21, 2017

WordPress 4.7 Reaches 10 Million Downloads, Releases New Security and Maintenance Update

WordPress 4.7 "Vaughan" has been downloaded over 17 million times since December 6, 2016! https://smallbiztrends.com/2017/01/wordpress-download-numbers.html

The latest version of WordPress is proving to be a hit with users. At over 10 million, the WordPress download numbers has broken a new milestone.

Originally posted at The WP Guy - WordPress Web Design

January 17, 2017

Video: How to Link to an Email Address in WordPress



WPBeginner - WordPress Tutorials originally appeared at http://www.youtube.com/watch?v=cdaUPQIdfgQ

January 12, 2017

Amazon Associates Link Builder

Amazon Releases Associates Link Builder plugin for WordPress Amazon has just announced their first official plugin for WordPress – the Amazon Associates Link Builder. The Link Builder plugin makes it easier to search for, and link to, products on Amazon without leaving WordPress. It connects to Amazon's real-time Product Advertising API, which means that all information found in the Link Builder will be current and accurate including prices, images, and product availability. The Link Builder plugin is currently in open beta. Amazon is requestion that bug reports or suggestions be submitted to link-builder@amazon.com (this email is for plugin feedback only). Click here to download the plugin for free: https://wordpress.org/plugins/amazon-associates-link-builder/ Get the accompanying user guide PDF here: https://s3.amazonaws.com/aalb-public-resources/documents/AssociatesLinkBuilder-UserGuide.pdf Find the community support forum at: https://wordpress.org/support/plugin/amazon-associates-link-builder

The official plugin from the Amazon Associates Program.

Originally posted at The WP Guy - WordPress Web Design

January 11, 2017

WordPress 4.7.1 Security and Maintenance Release

WordPress 4.7 has been downloaded over 10 million times since its release on December 6, 2016 and we are pleased to announce the immediate availability of WordPress 4.7.1. This is a security release for all previous versions and we strongly encourage you to update your sites immediately.

WordPress versions 4.7 and earlier are affected by eight security issues:

  1. Remote code execution (RCE) in PHPMailer – No specific issue appears to affect WordPress or any of the major plugins we investigated but, out of an abundance of caution, we updated PHPMailer in this release. This issue was reported to PHPMailer by Dawid Golunski and Paul Buonopane.
  2. The REST API exposed user data for all users who had authored a post of a public post type. WordPress 4.7.1 limits this to only post types which have specified that they should be shown within the REST API. Reported by Krogsgard and Chris Jean.
  3. Cross-site scripting (XSS) via the plugin name or version header on update-core.php. Reported by Dominik Schilling of the WordPress Security Team.
  4. Cross-site request forgery (CSRF) bypass via uploading a Flash file. Reported by Abdullah Hussam.
  5. Cross-site scripting (XSS) via theme name fallback. Reported by Mehmet Ince.
  6. Post via email checks mail.example.com if default settings aren’t changed. Reported by John Blackbourn of the WordPress Security Team.
  7. A cross-site request forgery (CSRF) was discovered in the accessibility mode of widget editing. Reported by Ronnie Skansing.
  8. Weak cryptographic security for multisite activation key. Reported by Jack.

Thank you to the reporters for practicing responsible disclosure.

In addition to the security issues above, WordPress 4.7.1 fixes 62 bugs from 4.7. For more information, see the release notes or consult the list of changes.

Download WordPress 4.7.1 or venture over to Dashboard → Updates and simply click “Update Now.” Sites that support automatic background updates are already beginning to update to WordPress 4.7.1.

Thanks to everyone who contributed to 4.7.1: Aaron D. Campbell, Aaron Jorbin, Adam Silverstein, Andrea Fercia, Andrew Ozz, bonger, Boone Gorges, Chandra Patel, David Herrera, David Shanske, Dion Hulse, Dominik Schilling (ocean90), DreamOn11, Edwin Cromley, Ella van Dorpe, Gary Pendergast, James Nylen, Jeff Bowen, Jeremy Felt, Jeremy Pry, Joe McGill, John Blackbourn, Keanan Koppenhaver, Konstantin Obenland, laurelfulford, Marin Atanasov, mattyrob, monikarao, Nate Reist, Nick Halsey, Nikhil Chavan, nullvariable, Payton Swick, Peter Wilson, Presskopp, Rachel Baker, Ryan McCue, Sanket Parmar, Sebastian Pisula, sfpt, shazahm1, Stanimir Stoyanov, Steven Word, szaqal21, timph, voldemortensen, vortfu, and Weston Ruter.



WordPress 4.7.1 Security and Maintenance Release was originally posted at https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/

January 9, 2017

Video: How to Properly Setup Google AMP on Your WordPress Site



WPBeginner - WordPress Tutorials originally appeared at http://www.youtube.com/watch?v=0f5EA0y285w

January 3, 2017

Video: How to Add Underline and Justify Text Buttons in WordPress



WPBeginner - WordPress Tutorials originally appeared at http://www.youtube.com/watch?v=p8uaIUFYNOU