WordPress 4.7-p1 - CVE-2016-10033
Incident Report for Pantheon Operations
Resolved
Pantheon has released WordPress 4.7-p1, a security patch release of WordPress 4.7 to fix CVE-2016-0033[1]. At the time of this writing, WordPress had not yet released a fix for this CVE. Pantheon will replace this patch release with the official WordPress security release once it is available. Pantheon has made the update available for one-click update in site dashboards. We urge all users to update all environments as soon as possible. Instructions for applying core updates can be found in our Support Center.[2]

[1] - http://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html
[2] - https://pantheon.io/docs/upstream-updates/
Posted Dec 27, 2016 - 14:52 PST