Security fixes are made in the latest release only.
Please do not report security vulnerabilities through public GitHub issues or pull requests.
Report them through Automattic's HackerOne programme instead: https://hackerone.com/automattic
Reporting through HackerOne can also make you eligible for Automattic's bug bounty. Please read the bounty eligibility guidelines before submitting reports.
Please include:
- a description of the vulnerability and its impact
- steps to reproduce it
- a suggested fix, if you have one