Major Vulnerability Hits WordPress

LOS ANGELES — A vital security warning has been issued to the many users of self-hosted WordPress installations — a user base that includes countless adult websites.

In addition to affecting WordPress users, the exploit, which employs an XML Quadratic Blowup Attack, also affects users of the Drupal platform, which while relatively popular, does not have the vast market share of the Open Source WordPress solution — which may be adult entertainment’s most widely used content management system (CMS) and publishing platform.

As an example of the platform’s overall reach, recent World Wide Web Consortium (WC3) statistics reveal that 23 percent of today’s web is powered by WordPress.

The exploit is capable of immediately crashing a website, by causing complete usage of available CPU power and memory, while also causing a Denial of Service attack on the software’s MySQL database — but fortunately, this attack can be defeated by simply updating the software to its latest version.

The WordPress security team has now released the WordPress 3.9.2 system update and is strongly encouraging users to update their sites immediately. The Drupal security team has likewise issued a fix and also recommends users immediately update to its latest version.

The exploit was discovered by Salesforce.com security expert Nir Goldshlager, who explains that this attack inflates a small XML document of several hundred kilobytes into multiple gigabytes, crushing any Apache server in a matter of moments.

“If an attacker defines the entity ‘&x;’ as 55,000 characters long, and refers to that entity 55,000 times inside the ‘DoS’ element, the parser ends up with an XML Quadratic Blowup attack payload slightly over 200 KB in size that expands to 2.5 GB when parsed,” Goldshlager says. “This expansion is enough to take down the parsing process.”

Goldshlager has released a video demonstrating the attack in action.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

AEBN Publishes Popular Searches for November, December

AEBN has released the top search terms for the months of November and December from its straight and gay theaters in all 50 states and the District of Columbia.

Professor Fired Over Adult Content Sues U Wisconsin

Veteran communications professor Joe Gow this week filed a civil lawsuit against the University of Wisconsin board of regents for violating his First Amendment rights by firing him for creating and appearing in adult content.

Teasy Agency Launches 'WannaCollab' Networking Platform

Teasy Agency launched a new networking platform, WannaCollab, at the X3 Expo earlier this month.

Ofcom to Hold Online Sessions on OSA Compliance

U.K. communications regulator Ofcom will hold an online conference Feb. 3-5, titled “The Online Safety Act Explained: How to Comply,” explaining new duties and deadlines required of adult businesses to implement age assurance under the Online Safety Act (OSA).

FSC Announces Support for North Dakota Age Verification Bill

Free Speech Coalition (FSC) has announced its support for SB 2380, North Dakota's new age verification bill.

Oklahoma State Senator Introduces Bill to Criminalize All Porn, Jail Creators

Oklahoma Senator Dusty Deevers has introduced a bill that would criminalize all adult content and authorize the state to imprison those who create or view it.

Adult Time Releases 2024 'Year in Review' Report

Adult Time has released its Year in Review report, highlighting the studio's audience favorites from throughout 2024.

AEBN Reveals Ariel Demure as Top Trans Star for Q4 of 2024

AEBN has named its top trans stars for the fourth quarter of 2024, with Ariel Demure landing atop the leaderboard.

WOWify.AI Joins ASACP as Corporate Sponsor

WOWify.AI has signed on as the latest corporate sponsor for the Association of Sites Advocating Child Protection (ASACP).

Segpay Adds Gateway Payment Solution

Segpay has added the Gateway option to its direct payments solutions.

Show More