Home
»
Hackers News Portal
» Wordpress 4.2.3 Security Update Released , Patches Critical Vulnerability.
WordPress has just released the new version of its content management system (CMS), WordPress version 4.2.3,
to fix a critical security vulnerability that could have been exploited
by hackers to take over websites, affecting the security of its
Millions of sites.
WordPress version 4.2.3 resolves a Cross-Site Scripting (XSS) flaw
that could allow any user with the Contributor or Author role to
compromise a website, Gary Pendergast of the WordPress team wrote in a blog post on Thursday.
Cross-site scripting is actually a vulnerability in the Web
applications' code that opens up the target website to attacks. The
vulnerability is one of the most favorite and commonly used flaws by
cyber criminals.
According to the company, the vulnerability could allow hackers to embed maliciously-crafted HTML, JavaScript, Flash, or other code to bypass WordPress's kses protection by fooling users into executing a malicious script on their computer system.
This, in turn, leads to the collection of users' sensitive data, including cookies stored on their systems.
It is still unknown exactly how websites could be compromised using the
flaw, as more details about the vulnerability aren't yet made available
by the company.
All versions of WordPress from 4.2.2 and earlier are affected by the flaw, but you need not worry about it if you have Automatic Security Updates enabled.
However, if not, you are strongly recommended to update your WordPress CMS to version 4.2.3 as soon as possible.
To Update WordPress, all you need to do is just go to the main WordPress "Dashboard", then "Updates" and click "Update Now." And you are done.
About Author
The part time Blogger love to blog on various categories like Web Development, SEO Guide, Tips and Tricks, Android Stuff, etc including Linux Hacking Tricks and tips. A Blogger Template Designer; designed many popular themes.
Advertisement
Related Posts
- NSA Data Center Utah Experiencing About 300 Million Hacking Attempts Per Day - Hackers News Portal23 Feb 20160
Utah State computer systems are experiencing a massive cyber attack on up to 300 Million Ha...Read more »
- Russian Planning To Kick Out Foreign Tech Companies Ou of Nation - via Hackers News Portal14 Feb 20160
Someone wants to kick Microsoft, Google and Apple off from his land, but himself uses Gmail an...Read more »
- 16-year-old Boy Got Arrested by Police in Case Of Hacking Down CIA Director - Hackers News Portal13 Feb 20160
The teenage hacker, who calls himself a member of hacktivist group "Cracka with Attitude," ...Read more »
- Serious, Yet Patched Flaw Exposes 6.1 Million IoT Devices to Hackers Remote Code Execution - Hackers News Portal06 Dec 20150
As much as you protect your electronics from being hacked, hackers are clever enough at findi...Read more »
- FBI reportedly Paid $1 Million to University Researchers for UnMasking Tor Users - Hackers News Portal13 Nov 20150
The non-profit Tor Project has accused the FBI of paying the security researc...Read more »
- Hacking Fitbit Health Trackers Wirelessly in 10 Seconds - Hackers News Portal26 Oct 20150
Do you need a FitBit Tracker while jogging or running or even sleeping? Bad News! FitBit can...Read more »