Skip to content
  • Home
    • Wisconsin Citizens for Science
  • WordPress
  • eCommerce
  • CMS
Blank ThemeCMS, WordPress and eCommerce Theme News
  • Home
    • Wisconsin Citizens for Science
  • WordPress
  • eCommerce
  • CMS
on April 30, 2020

WordPress Vulnerability Update – Search Engine Journal

WordPress

ADVERTISEMENT

WordPress announced an update that fixes seventeen bug fixes and seven vulnerabilities. WordPress is automatically updating sites to WordPress 5.4.1.

It is important to check that your WordPress installation is updated to version WordPress 5.4.1.

Cross-site Scripting Vulnerabilities

WordPress patched it’s software to address multiple Cross-site scripting (XSS) vulnerabilities. There are two kinds, XSS and Authenticated XSS.

A cross-site scripting (XSS) vulnerability allows an attacker to inject a malicious script on a vulnerable web page.

An authenticated cross-site scripting (Authenticated XSS) is the same vulnerability only this one happens when a user is logged in. The user can be anyone ranging from a site member all the way up to the administrator level.

XSS vulnerabilities can be used to attack site visitors as well as to alter a WordPress web page. These kinds of vulnerabilities can be used as the first wave of attack that can unlock and clear the way for more serious attacks.

For that reason it’s important to stay on top of XSS vulnerabilities and keep your WordPress installation patched to the very latest version.

The software update was not not limited to fixing XSS vulnerabilities. There were other kinds of vulnerabilities as well.

Not All Sites Automatically Updated

WordPress announced that WordPress installations from WordPress 3.7 and up have been automatically updated. That means WordPress installations lower than 3.7 were not automatically updated.

The official WordPress announcement implies that versions less than 3.7 remain vulnerable, since this vulnerability affects all WordPress versions under 5.4.
It is prudent to update any older WordPress installations to the very latest in order to avoid any previous WordPress vulnerabilities.

According to the official WordPress announcement:

“This security and maintenance release features 17 bug fixes in addition to 7 security fixes. Because this is a security release, it is recommended that you update your sites immediately.”

Bug Fixes

There were 17 bug fixes in this release. Typical bugs that were fixed were broken media file uploads affecting certain browsers  and fixing conflicts with some plugins, among many other bugs.

Read the official WordPress announcement here:

WordPress 5.4.1

WordPress 5.4.1

Category

No comments

Latest News

  • Shopify (TSX:SHOP) Stock: Ready to Make $1 Million? – The Motley Fool Canada
  • What WordPress Templates help you Sell more online? | South Florida Caribbean News – South Florida Caribbean News
  • Shepherd Public Schools plans online and in-person learning options for the upcoming school year – The Morning Sun
  • WordPress Accessibility! – coloradoboulevard.net
  • Persistent WordPress User Injection – Security Boulevard

Advertisement

Keystone Natural Health - Check out our latest article.

Past News

  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • March 2018