This is a security release that features several fixes.
Because this is a security release, it is recommended that you update your sites immediately.
You can download WordPress 6.9.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, the update process will begin automatically.
The next major release will be version 7.0, which is planned for April 9th, 2026.
For more information on WordPress 6.9.2, please visit the version page on the HelpHub site.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
query-attachments authorization bypass reported by Vitaly Simonovichdata-wp-bind directive reported by kaminumaThe WordPress security team have worked with the maintainer of the external getID3 library, James Heinrich, to coordinate a fix to getID3. A new version of getID3 is available here.
As a courtesy, these fixes are being backported, where necessary, to all branches eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported. The backports are in progress and will ship as they become ready.
This release was led by John Blackbourn. In addition to the security researchers mentioned above, WordPress 6.9.2 would not have been possible without the contributions of the following people: Dennis Snell, Alex Concha, Jon Surrell, Isabel Brison, Peter Wilson, Jonathan Desrosiers, Jb Audras, Luis Herranz, Aaron Jorbin, Weston Ruter, and Dominik Schilling.
Applications are now open for the 2026 Kim Parsell Memorial Scholarship, which supports one active…
This post recaps how the WordPress project’s five Global Partners — Jetpack, WordPress.com, WooCommerce, Bluehost,…
The full chat log is available beginning here on Slack. WordPress Performance Trac tickets @westonruter…
WordCamp Europe, the biggest WordPress conference in Europe, spent the first week of June in…
tl;dr: Temporary 24-hour cooldown period for plugin/theme releases before auto-updates. AI can give defenders an…
The full chat log is available beginning here on Slack. WordPress Performance Trac tickets @b1ink0…