Blog | G5 Cyber Security

WordPress 4.2.3 released, fixing critical security hole. Update!

WordPress has just released version 4.2.3, a security and maintenance update for all previous versions of the software. The latest security update is in how shortcodes are used in HTML attributes. This could enable maliciously-crafted shortcodes to bypass WordPresss kses code which is designed to strip bad stuff out of HTML, by tricking it into thinking the code is valid. The vulnerability may allow users without the unfiltered_html capability, but with publishing rights, to run JavaScript code on the front end of the website.”]

Source: https://grahamcluley.com/wordpress-4-2-3-security-update/

Exit mobile version