Blog | G5 Cyber Security

WordPress Vulnerability Puts Millions of Websites At Risk

The vulnerability resides in Genericons webfont package that is part of default WordPress Twenty Fifteen Theme. The easy-to-exploitoccurred due to an insecure file included with Genericons that allowed the Document Object Model Environment in the victim’s browser to be modified. The vulnerability is actively being exploited in the wild and so far, the researcher has discovered JetPack plugin and Twenty Fif15 theme to be vulnerable to a DOM-based XSS attack. Administrators of WordPress sites should check if their site is running the Genericons package.

Source: https://thehackernews.com/2015/05/wordPress-vulnerability.html

Exit mobile version