WordPress 4.2.3 Update Released to Patch a Major XSS Vulnerability

Advertisement
By Manish Singh | Updated: 24 July 2015 17:01 IST
WordPress has rolled out a new version dubbed 4.2.3 of its content management system (CMS) to patch a critical cross-site scripting (XSS) vulnerability affecting all the existing versions. The blogging platform, which powers more than 60 million websites, urges all webmasters to update their sites.

The XSS vulnerability in question could have been exploited by any user marked "author" or "contributor" to fully compromise the site's security. The company didn't reveal the specifics around the vulnerability.

Advertisement
The WordPress update also fixes a recently discovered bug that allowed any subscriber to create blog posts on the site using management system's Quick Draft mechanism. The company says that the new update squashes 20 bugs.

Earlier this month, the company fixed several vulnerabilities in its plugins that could have been exploited to execute arbitrary code to steal sensitive information.

Advertisement
This is the second major vulnerability discovered in WordPress this year. In May, a major vulnerability was found in ThirtyFifteeen theme and the JetPack plugin, which affected about a million users.

The good thing about these updates is that they don't take much effort to implement. The blogging platform lets webmasters update to the latest version by simply clicking on the Update Now button.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Internet, malware, wordpress
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Nord 6 Could Launch in India at This Price
  2. Huawei MatePad SE 11 Set to Launch at This Price in India
  3. Here's When the Vivo X300 Ultra and Vivo X300s Will Be Launched
  4. WhatsApp Could Soon Bring Noise Cancellation for Video, Voice Calls
  5. Vivo V70 FE Could Launch in India Next Month at This Price
  6. Dreame L40 Ultra AE, Dreame D20 Ultra Robot Vacuum Launched in India
  7. Huawei Teases MatePad 11.5 Price in India Ahead of Launch
  1. Vivo X300 Ultra and Vivo X300s Launch Date Announced as Company Teases Designs
  2. iQOO Z11, iQOO Z11x China Launch Date Announced: Expected Features, Specifications
  3. Fortnite Returns to Google Play Store for Android Users Worldwide
  4. WhatsApp Beta Update Reportedly Adds Noise Cancellation for Video, Voice Calls on Android
  5. Russia Plans Venera-D Mission to Venus in 2036 With Lander, Orbiter, and Balloon Probe
  6. Realme C100i Spotted on NBTC Certification Database as Key Features Surface Online via Retailer Listings
  7. Huawei MatePad SE 11 Price in India Revealed as Company Confirms Imminent Launch in the Country
  8. Marshall Bromley 450 Launched in India With 360-Degree Sound, Up to 40-Hour Battery Life: Price, Features
  9. Oppo Find X9s Pro Reportedly Bags 3C Certification Ahead of Launch in China: Expected Specifications
  10. Itel Unveils Zeno AI Weaver Voice Recorder in India With Up to 40 Hours Recording Capacity, Live Transcription
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.