Menu
WordPress silently fixes dangerous code injection vulnerability

WordPress silently fixes dangerous code injection vulnerability

The flaw could allow unauthenticated users to modify any post or page in a WordPress site

Developers of the widely used WordPress content management system released an update last week, but intentionally delayed announcing that the patch addressed a severe vulnerability.

WordPress version 4.7.2 was released on January 26 as a security update, but the accompanying release notes only mentioned fixes for three moderate risk vulnerabilities, one of which did not even affect the platform's core code.

On Wednesday, a week later, the WordPress security team disclosed that a fourth vulnerability, much more serious than the others, was also patched in version 4.7.2.

The vulnerability was discovered by researchers from web security firm Sucuri and was reported privately to the WordPress team on January 20. It's located in the platform's REST API (application programming interface) and allows unauthenticated attackers to modify the content of any post or page within a WordPress site.

"We believe transparency is in the public’s best interest," WordPress core developer Aaron Campbell said in a blog post Wednesday. "It is our stance that security issues should always be disclosed. In this case, we intentionally delayed disclosing this issue by one week to ensure the safety of millions of additional WordPress sites."

According to Campbell, after learning about the flaw, the WordPress developers reached out to security companies that maintain popular web application firewalls (WAFs) so they can deploy protection rules against possible exploits. They then contacted large WordPress hosting companies and advised them on how to implement protections for their customers before an official patch was released.

The vulnerability only affects WordPress 4.7 and 4.7.1, where the REST API is enabled by default. Older versions are not affected, even if they have the REST API plug-in.

"We’d also like to thank the WAFs and hosts who worked closely with us to add additional protections and monitored their systems for attempts to use this exploit in the wild," Campbell said. "As of today, to our knowledge, there have been no attempts to exploit this vulnerability in the wild."

While that's good news, it doesn't mean that attackers won't start exploiting this vulnerability now that the information is out. WordPress is the most popular website building platform, which makes it a very attractive target for hackers.

Webmasters should make sure that they update their WordPress sites to version 4.7.2 as soon as possible if they haven't done it yet.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Featured

Slideshows

Meet the leading female front runners of the Kiwi channel

Meet the leading female front runners of the Kiwi channel

Reseller News honoured the leading female front runners of the New Zealand channel at the 2018 Women in ICT Awards (WIICTA) in Auckland. The awards honoured standout individuals across seven categories, spanning Entrepreneur; Innovation; Rising Star; Shining Star; Community; Technical and Achievement.

Meet the leading female front runners of the Kiwi channel
Meet the top performing customer-centric Microsoft channel partners

Meet the top performing customer-centric Microsoft channel partners

Microsoft honoured leading partners across the channel following a year of customer innovation and market growth in New Zealand. The 2018 Microsoft Partner Awards recognised excellence within the context of the end-user, spanning a host of emerging and established providers.

Meet the top performing customer-centric Microsoft channel partners
Reseller News launches new-look Awards at 2018 Judges’ Lunch

Reseller News launches new-look Awards at 2018 Judges’ Lunch

Introducing the Reseller News Innovation Awards, launched to the channel at the 2018 Judges’ Lunch in Auckland. With more than 70 judges now part of the voting panel, the new-look awards will reflect the changing dynamics of the channel, recognising excellence across customer value and innovation - spanning start-ups, partners, distributors and vendors.

Reseller News launches new-look Awards at 2018 Judges’ Lunch
Show Comments