Menu
WordPress quickly patches second critical vulnerability

WordPress quickly patches second critical vulnerability

It's the second time in a week WordPress had fixed flaws involving malicious comments

WordPress patched a second critical vulnerability in its Web publishing platform on Monday, less than a week after fixing a similar problem.

Administrators are advised to upgrade to WordPress version 4.2.1. Some WordPress sites that are compatible with and use a plugin called Background Update Tester will update automatically.

WordPress is one of the most-used Web publishing platforms. By the company's own estimation, it runs 23 percent of the sites on the Internet, including major publishers such as Time and CNN.

The latest flaw was found by Jouko Pynnönen[cq] of Klikki Oy, a Finish software company. Pynnönen found WordPress was vulnerable to a cross-site scripting flaw if an attacker inserted malicious JavaScript into a comments field. The script runs when someone views the comment, according to an advisory.

Cross-site scripting flaws are among the most dangerous and common Web vulnerabilities, allowing rogue code to run that should be forbidden.

If a WordPress administrator is logged in when the malicious comment is viewed, the attacker can then execute arbitrary code on the server through the plugin and theme editors. It is also then possible to change the administrator's password, create new administrator accounts or manipulate content on a site. The vulnerability can't cause damage from an ordinary reader viewing the comment.

Klikki Oy alleged that WordPress had stopped communicating with it last November when Klikki found a different vulnerability in WordPress. With the latest flaw, Klikki said it had also tried to notify WordPress through the Finnish computer security authority, CERT-FI, and HackerOne, which offers a service for managing vulnerability reports and rewards.

On April 21, WordPress patched a vulnerability similar to the one Pynnönen came across. Cedric Van Bockhaven[cq] found that WordPress was vulnerable to a cross-site scripting attack involving comments due to a MySQL database behavior it allowed.

He found that rogue code could be executed when a person hovered over a malicious script inserted into a comments field. Proof-of-concept code written by Van Bockhaven showed how a new user could be added in the administration panel. The flaw could also be used to download a plugin that runs malicious server-side code, he wrote on his blog.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Error: Please check your email address.

Tags securityWordpressExploits / vulnerabilitiesKlikki Oy

Featured

Slideshows

Looking back at the top 15 M&A deals in NZ during 2017

Looking back at the top 15 M&A deals in NZ during 2017

In 2017, merger and acquisitions fever reached new heights in New Zealand, with a host of big name deals dominating the headlines. Reseller News recaps the most important transactions of the Kiwi channel during the past 12 months.

Looking back at the top 15 M&A deals in NZ during 2017
Kiwi channel closes 2017 with After Hours

Kiwi channel closes 2017 with After Hours

The channel in New Zealand came together to celebrate the close of 2017, as the final After Hours played out in front of a bumper Auckland crowd.

Kiwi channel closes 2017 with After Hours
Meet the top performing HP partners in NZ

Meet the top performing HP partners in NZ

HP honoured leading partners across the channel at the Partner Awards 2017 in New Zealand, recognising excellence across the entire print and personal systems portfolio.

Meet the top performing HP partners in NZ
Show Comments