* WordPress 4.7.3 is now available. WordPress versions 4.7.2 and earlier are affected by six security issues:
* Cross-site scripting (XSS) via media file metadata. Reported by Chris Andre Dale, Yorick Koster, and Simon P. Briggs.
* Control characters can trick redirect URL validation. Reported by Daniel Chatfield.
* Unintended files can be deleted by administrators using the plugin deletion functionality. Reported by xuliang.
* Cross-site scripting (XSS) via video URL in YouTube embeds. Reported by Marc Montpas.
* Cross-site scripting (XSS) via taxonomy term names. Reported by Delta.
* Cross-site request forgery (CSRF) in Press This leading to excessive use of server resources. Reported by Sipke Mellema.
* This release includes new features:
* WordPress expects an existing database to be configured with.
* The following plugins have been added:
- akismet
- all-in-one-wp-migration
- all-in-one-seo-pack
- google-analytics-for-wordpress
- jetpack
- simple-tags
- wordpress-mu-domain-mapping