Samuel Sidler reports:
	  WordPress 4.3.1 is now available. This is a security
	    release for all previous versions and we strongly
	    encourage you to update your sites immediately.
	  
	    - WordPress versions 4.3 and earlier are vulnerable
	      to a cross-site scripting vulnerability when processing
	      shortcode tags (CVE-2015-5714). Reported by Shahar Tal
	      and Netanel Rubin of Check Point.
- A separate cross-site scripting vulnerability was found
	      in the user list table. Reported by Ben Bidner of the
	      WordPress security team.
- Finally, in certain cases, users without proper
	      permissions could publish private posts and make
	      them sticky (CVE-2015-5715). Reported by Shahar Tal
	      and Netanel Rubin of Check Point.