Version 4.1.6 - Main Page « WordPress Codex
From the announcement post, WordPress 4.1.6 fixes a cross-site scripting vulnerability, which could allow users with the Contributor or Author role to compromise a site. The release also fixes an issue where it was possible for a user with Subscriber permissions to create a draft through Quick Draft.