Get a Pentest and security assessment of your IT network.

News

WordPress fixed a Zero Day a few hours after its disclosure

WordPress has just released a critical update to fix a serious XSS vulnerability that allows attackers to easily hijack websites based on the popular CMS. An unauthenticated attacker can inject JavaScript in WordPress comments. The script is triggered when the comment is viewed by a logged-in administrator. WordPress hasnt recognized the security flaw since it was first submitted in November of 2014 via the CERT-FI and HackerOne. WordPress has already released the version 4.2.1, the critical update that fixes the flaw.”]

Source: http://securityaffairs.co/wordpress/36360/hacking/wordpress-4-2-1-fixed-zero-day.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Wikileaks Vault 7 Imperial projects revealed the 3 hacking tools Achilles, SeaPea and Aeris