WordPress 4.4.1 fixes a worrisome cross-site scripting (XSS) issue, while problems with the update manager in Drupal 7 and 8 remain at large. The fix was reported to parent company Automattic via a Philippines-based security researcher known only as Crtc4L. If exploited, cybercriminals can trick administrators into sending unlimited requests to the Drupal update server and quickly consume available bandwidth. Drupal developers have announced theyre working on a fix for the CSRF and status update vulnerabilities.”]
Source: https://securityintelligence.com/news/new-year-new-problems-cms-vulnerabilites-take-on-2016/

