WordPress Vulnerability Affects Millions of Websites; Fix Issued

Advertisement
By Ketan Pratap | Updated: 8 May 2015 18:50 IST
Security researchers have discovered vulnerabilities in the default installation of WordPress, leaving sites that use content management system open to attack - specifically a critical cross-site scripting vulnerability that allows anonymous users to compromise the site.

David Dede from Sucuri security research company has claimed that any WordPress theme or plugin that runs a genericons package is at risk. Dede adds that the one of the default themes for WordPress, TwentyFifteen, as well as the JetPack plugin, use the genericons icon fonts package.

The vulnerability can allow attackers to hack into any WordPress website using the default theme and plugin if the administrator accidentally clicks on a malicious link. The genericons package comes with an insecure file that makes the site open to cross-site scripting vulnerability.

The firm on Thursday released version 4.2.2 update which is basically a security and maintenance release targeted to fix the vulnerability. The latest release addresses two security issues including updated genericons used in default themes and plugins that scan the WordPress content directory for the affected (and "nonessential") example.html file and removes it.

Advertisement

Dede of Sucuri tried to demystify the vulnerability and explains, "The XSS vulnerability is very simple to exploit and happens at the Document Object Model (DOM) level. DOM-Based XSS is an XSS attack wherein the attack payload is executed as a result of modifying the Document Object Model (DOM) "environment" in the victim's browser used by the original client side script, so that the client side code runs in an "unexpected" manner. That is, the page itself (the HTTP response that is) does not change, but the client side code contained in the page executes differently due to the malicious modifications that have occurred in the DOM environment."

Advertisement

The security firm has also listed few hosts that have also patched the issue recently including GoDaddy, HostPapa, DreamHost, ClickHost, Site5, and SiteGround among others.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Further reading: Internet, Vulnerability, WordPress
Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Realme 16 Pro Series Could Cost in India
  2. Samsung Galaxy S26 Ultra Tipped to Launch With These Camera Improvements
  3. Hearing Static Noise on Your iPhone 17 Pro Max? You're Not Alone
  4. TCL Note A1 Nxtpaper E-Note Launched at This Price to Rival Kindle Scribe
  5. Moto X70 Air Pro Teaser Confirms AI Focus and Pro Upgrade
  6. Redmi Pad 2 Pro 5G Price Range, Chipset Revealed Ahead of Launch in India
  7. What is HDFC Bank Statement Password: How to Open Statement PDF, More
  8. OnePlus 16 Could Feature Same Cameras as the Rumoured Oppo Find N6
  9. Meta Adds Manus to Its AI Portfolio in Its Fifth 2025 Acquisition
  10. Innocent (2025) Now Available For Streaming Online: What You Need to Know
  1. Meta Acquires Autonomous Agent Developer Manus AI, Marks Its Fifth Deal in 2025
  2. Apple Patent Suggests AR Smart Glasses Could Offer Improved Comfort With Adjustable Arms
  3. Xiaomi Mix 5 Tipped to Launch With Quad Curved Screen, Under-Display Selfie Camera With 3D Facial Recognition
  4. MIT Develops 3D-Printable Aluminum Alloy That’s Up to Five Times Stronger Than Conventional Metals
  5. iPhone 17 Pro, iPhone 17 Pro Max Users Report Charging-Related Static Speaker Noise
  6. Celestis to Send Human Ashes Beyond the Moon on Deep-Space Memorial Flight in 2026
  7. Realme 16 Pro, Realme 16 Pro+ Price in India, Storage Configurations Leaked
  8. Lenovo Yoga Slim 7x, IdeaPad 5x 2-in-1, IdeaPad Slim 5x With Snapdragon X2 Chips to Launch at CES 2026: Report
  9. TCL Note A1 Nxtpaper E-Note Launched With 8,000mAh Battery, 11.5-Inch Display: Price, Specifications
  10. Samsung Partners With Nota AI to Enable Advanced On-Device AI on Exynos 2600 Chip
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.