Search This Blog
Popular Posts
-
Elegant Themes has been developing WordPress themes for a long time. It has developed lots of popular themes including Divi, Nexus, Fa...
-
This is part of our "Learn WordPress" series. In this post, you will find out how to properly set up WordPress after creati...
-
It has not only changed the traditional perspective of buyers and sellers, but also revolutionized the entire concept of retail busine...
-
Lifegate is a modern looking and elegant WordPress Blog Theme with plenty of straightforward and complete functionalities to build up a pe...
-
WordPress has rolled out a new version dubbed 4.2.3 of its content management system (CMS) to patch a critical cross-site scripting (XSS) vu...
-
Hello there! My blog post 'Spikes' was published on Sept. 22nd; however, the post before it called 'Flow' was published on...
-
LIST MAG WP is a beautifully designed WordPress Theme that is built to be engaging, fast and most importantly boost viral traffic with...
-
The United States government earlier this year officially accused Russia of interfering with the US elections. Earlier this year on Octo...
-
What comes to mind when you hear of WordPress? For a majority of people, blogging comes to mind. To other people who are professionals in we...
-
A Guide to Building WordPress on Docker for Windows, Linux and OS X Michael McCallister December 28, 2016 #containerization #docker...
Blog Archive
- December (18)
- November (29)
- October (27)
- September (29)
- August (31)
- July (30)
- June (29)
- May (29)
- April (30)
- March (31)
- February (28)
- January (31)
- December (31)
- November (30)
- October (31)
- September (30)
- August (43)
- July (42)
- June (33)
- May (43)
- April (36)
- March (37)
- February (31)
- January (4)
- December (1)
- November (1)
- October (24)
- September (24)
- August (25)
- July (28)
- June (18)
- September (1)
Total Pageviews
Blogroll
Jetpack plug-in for WordPress vulnerable to XSS
Bloggers using the WordPress platform are being advised to update the Jetpack plug-in to avoid a cross-site scripting vulnerability.
One million users of the plug-in – which was developed by Automattic, the makers of WordPress – could be at risk. The tool provides website enhancements, management and security features.
The flaw – which impacts Jetpack releases since 2012, beginning with v2.0 – was detected by web security firm Sucuri. The bug is located in the Shortcode Embeds Jetpack module, a shortcut function enabled by default that allows users to embed videos, images, documents, tweets and other materials.
The Sucuri researchers said this flaw can be exploited to inject malicious JavaScript code into comments. Subsequently, it "could allow an attacker to hijack administrator accounts, inject SEO spam to the affected page, and redirect visitors to malicious websites," Sucuri noted in a blog post.
Update as soon as possible, said the researchers.
Source: Jetpack plug-in for WordPress vulnerable to XSS
0 comments:
Post a Comment