WordPress Vulnerability Affects Millions of Websites; Fix Issued

Advertisement
By Ketan Pratap | Updated: 8 May 2015 18:50 IST
Security researchers have discovered vulnerabilities in the default installation of WordPress, leaving sites that use content management system open to attack - specifically a critical cross-site scripting vulnerability that allows anonymous users to compromise the site.

David Dede from Sucuri security research company has claimed that any WordPress theme or plugin that runs a genericons package is at risk. Dede adds that the one of the default themes for WordPress, TwentyFifteen, as well as the JetPack plugin, use the genericons icon fonts package.

The vulnerability can allow attackers to hack into any WordPress website using the default theme and plugin if the administrator accidentally clicks on a malicious link. The genericons package comes with an insecure file that makes the site open to cross-site scripting vulnerability.

The firm on Thursday released version 4.2.2 update which is basically a security and maintenance release targeted to fix the vulnerability. The latest release addresses two security issues including updated genericons used in default themes and plugins that scan the WordPress content directory for the affected (and "nonessential") example.html file and removes it.

Advertisement

Dede of Sucuri tried to demystify the vulnerability and explains, "The XSS vulnerability is very simple to exploit and happens at the Document Object Model (DOM) level. DOM-Based XSS is an XSS attack wherein the attack payload is executed as a result of modifying the Document Object Model (DOM) "environment" in the victim's browser used by the original client side script, so that the client side code runs in an "unexpected" manner. That is, the page itself (the HTTP response that is) does not change, but the client side code contained in the page executes differently due to the malicious modifications that have occurred in the DOM environment."

Advertisement

The security firm has also listed few hosts that have also patched the issue recently including GoDaddy, HostPapa, DreamHost, ClickHost, Site5, and SiteGround among others.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Further reading: Internet, Vulnerability, WordPress
Advertisement

Related Stories

Popular Mobile Brands
  1. Tecno Pop X Launched in India With 5,000mAh Battery, IP64 Rating: See Price
  2. MacBook Pro (2026) With M5 Pro, M5 Max Chips Launched in India: See Price
  3. Epson EpiqVision Mini EF-22N Review: A Premium Portable Laser Projector
  4. iPhone 17e vs Google Pixel 10a: Which Is a Better Option for You?
  5. MWC 2026 Roundup: The Most Important Announcements So Far
  1. Tecno Pop X Launched in India With 5,000mAh Battery, IP64 Rating: Price, Specifications
  2. Tecno Megapad 2, Tecno Watch GT 1S and Tecno FreeHear 2 Unveiled at MWC 2026: Availability, Features
  3. Mike & Nick & Nick & Alice OTT Release Date: Know When and Where to Watch it Online
  4. MediaTek Showcases AI Glasses at MWC 2026; Demonstrates Emergency Satellite Alerts With Starlink
  5. Devagudi Now Streaming Online: Where to Watch Intense Drama Online?
  6. Jab Khuli Kitaab OTT Release Date: When and Where to Watch Pankaj Kapur and Dimple Kapadia Starrer Romantic Drama Online?
  7. Apple Introduces M5 Pro, M5 Max Chips With New Fusion Architecture on 2026 MacBook Pro Models
  8. Apple Studio Display, Studio Display XDR With 27-Inch 5K Displays Launched in India: Price, Features
  9. Jockey Now Available for Streaming Online: Where to Watch This Tamil Action Movie Online?
  10. NASA’s Carruthers Observatory Begins Mission to Study Earth’s Hydrogen Halo
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.