WordPress 4.2.3 Update Released to Patch a Major XSS Vulnerability

Advertisement
By Manish Singh | Updated: 24 July 2015 17:01 IST
WordPress has rolled out a new version dubbed 4.2.3 of its content management system (CMS) to patch a critical cross-site scripting (XSS) vulnerability affecting all the existing versions. The blogging platform, which powers more than 60 million websites, urges all webmasters to update their sites.

The XSS vulnerability in question could have been exploited by any user marked "author" or "contributor" to fully compromise the site's security. The company didn't reveal the specifics around the vulnerability.

The WordPress update also fixes a recently discovered bug that allowed any subscriber to create blog posts on the site using management system's Quick Draft mechanism. The company says that the new update squashes 20 bugs.

Advertisement
Earlier this month, the company fixed several vulnerabilities in its plugins that could have been exploited to execute arbitrary code to steal sensitive information.

This is the second major vulnerability discovered in WordPress this year. In May, a major vulnerability was found in ThirtyFifteeen theme and the JetPack plugin, which affected about a million users.

The good thing about these updates is that they don't take much effort to implement. The blogging platform lets webmasters update to the latest version by simply clicking on the Update Now button.
 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Further reading: Internet, malware, wordpress
Advertisement

Related Stories

Popular Mobile Brands
  1. Here's When the Realme P4 Power 5G Will Launch in India
  2. Vivo X200T With Zeiss Cameras to Launch in India on This Date
  3. Redmi Note 15 Pro Series Might Launch in India With These Storage Options
  4. Samsung Galaxy S26 Ultra May Arrive in Six Colourways
  5. OnePlus 16 May Launch With These Display, Battery and Camera Upgrades
  6. Red Magic 11 Air Launched With Snapdragon 8 Elite, 7,000mAh Battery
  7. Motorola Edge 70 Fusion Leak Reveals Full Specifications Ahead of Launch
  8. Samsung Galaxy A57 Spotted on Certification Site With These Key Features
  1. Samsung Galaxy S26 Ultra May Arrive in Six Colourways, Tipster Claims
  2. Scientists Find Clue to High-Temperature Superconductivity in Quantum Materials
  3. New Dark Matter Simulation Could Change How Galaxies Are Thought to Evolve
  4. SpaceX Adds 29 More Starlink Satellites in Rapid Falcon 9 Launch From Florida
  5. Sony to Cede Control of Bravia TVs to China’s TCL Electronics
  6. Adobe Premiere Integrated With AI-Powered Firefly Platform; New After Effects Features Rolling Out
  7. Samsung Upgrades Bixby With Perplexity-Powered AI Features, Takes Page Out of Apple’s Playbook
  8. Google Reportedly Working On New Live Features and Agentic Mode for Gemini Assistant
  9. Redmi Note 15 Pro+, Redmi Note 15 Pro RAM and Storage Options, Key Specifications Leaked Ahead of India Launch
  10. Eddington Arrives on OTT: What You Need to Know About Joaquin Phoenix and Pedro Pascal Starrer Thriller
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.