Get a Pentest and security assessment of your IT network.

News

WordPress Core Engine Stored XSS Vulnerability Patched

A critical stored cross-site scripting zero-day vulnerability affecting tens of millions of WordPress sites has been patched in version 4.2.1. The vulnerability allowed for malicious JavaScript to be stored in comment fields and executed server-side. The comment has to be at least 66,000 characters long and it will be triggered when the comment is viewed, researcher Jouko Pynnonen said. WordPress said it has begun rolling out the update as an automatic background update on sites that support them.

Source: https://threatpost.com/wordpress-patches-zero-day-vulnerability/112455/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Reflection of cyber-attack to Wells Fargo in world media

News

CVE-2016-6563 RCE flaw affects D-Link Routers, disable remote admin