WordPress 4.7-p2 - CVE-2016-10045
Incident Report for Pantheon Operations
Resolved
Pantheon has released WordPress 4.7-p2, a security patch release of WordPress 4.7 to fix CVE-2016-10045[1]. At the time of this writing, WordPress had not yet released an official version containing a fix for this CVE. Pantheon will replace this patch release with the official WordPress security release once it is available. Pantheon has made the update available for one-click update in site dashboards. We urge all users to update all environments as soon as possible. Instructions for applying core updates can be found in our Support Center.[2]

[1] - https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10045-Vuln-Patch-Bypass.html
[2] - https://pantheon.io/docs/upstream-updates/
Posted Dec 29, 2016 - 11:38 PST