WordPress Vulnerability Affects Millions of Websites; Fix Issued

Advertisement
By Ketan Pratap | Updated: 8 May 2015 18:50 IST
Security researchers have discovered vulnerabilities in the default installation of WordPress, leaving sites that use content management system open to attack - specifically a critical cross-site scripting vulnerability that allows anonymous users to compromise the site.

David Dede from Sucuri security research company has claimed that any WordPress theme or plugin that runs a genericons package is at risk. Dede adds that the one of the default themes for WordPress, TwentyFifteen, as well as the JetPack plugin, use the genericons icon fonts package.

The vulnerability can allow attackers to hack into any WordPress website using the default theme and plugin if the administrator accidentally clicks on a malicious link. The genericons package comes with an insecure file that makes the site open to cross-site scripting vulnerability.

Advertisement

The firm on Thursday released version 4.2.2 update which is basically a security and maintenance release targeted to fix the vulnerability. The latest release addresses two security issues including updated genericons used in default themes and plugins that scan the WordPress content directory for the affected (and "nonessential") example.html file and removes it.

Dede of Sucuri tried to demystify the vulnerability and explains, "The XSS vulnerability is very simple to exploit and happens at the Document Object Model (DOM) level. DOM-Based XSS is an XSS attack wherein the attack payload is executed as a result of modifying the Document Object Model (DOM) "environment" in the victim's browser used by the original client side script, so that the client side code runs in an "unexpected" manner. That is, the page itself (the HTTP response that is) does not change, but the client side code contained in the page executes differently due to the malicious modifications that have occurred in the DOM environment."

Advertisement

The security firm has also listed few hosts that have also patched the issue recently including GoDaddy, HostPapa, DreamHost, ClickHost, Site5, and SiteGround among others.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Internet, Vulnerability, WordPress
Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  2. Poco M8s 5G Debuts Globally With 7,000mAh Battery: See Price, Features
  3. Apple's iOS 27 Update Might Drop Support for These iPhone Models
  4. Greenland 2 Migration OTT Release Date Confirmed: When and Where to Watch it Online?
  1. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  2. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  3. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  4. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  5. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  6. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  7. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
  8. Oppo Find X9s Pro Launched With 200-Megapixel Cameras, 7,025mAh Battery: Price, Specifications
  9. OnePlus Ace 6 Ultra Geekbench Listing Reveals MediaTek Dimensity 9500 Chip, 16GB RAM
  10. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.