WordPress Releases Critical Security Update

LOS ANGELES — Less than a week after the release of WordPress Version 4.2, a critical security update was released today — along with an admonition for all users to immediately update their installations.

Debuting on April 23, with a goal of improving WordPress’ communication, sharing and simplicity, Version 4.2, nicknamed “Powell” in honor of jazz pianist Bud Powell, offers easier ways to share content, while providing extended character support, enhanced embed options, and streamlined plugin updates.

Now, an emergency patch, Version 4.2.1, has been released to the public and is an update for all previous WordPress versions. The patch addresses a cross-site scripting vulnerability that could enable comment posters to compromise a site.

As for who is affected by this vulnerability, all WordPress-powered sites are at risk if they allow users to post comments via the integrated commenting system.

“An attacker could leverage a bug in the way comments are stored in the site’s database to insert malicious scripts on your site, thus potentially allowing them to infect your visitors with malware, inject SEO spam or even insert backdoor in the site’s code if the code runs when in a logged-in administrator browser,” Marc-Alexandre Montpas wrote for Sucuri.net, advising WordPress site admins to “definitely disable comments on your site until a patch is [installed] to protect your site and customers.”

The unexpected update fuels critics that claim the Open Source WordPress core lacks security, but the opposite is true: As the world’s most popular publishing platform, WordPress is actively embraced by tens of thousands of developers and used in countless websites, making its underlying code perhaps the most scrutinized software on the planet. This means that vulnerabilities are revealed and mitigated far more often than those contained in proprietary systems that are only well-known to a relative handful of developers and users.

WordPress 4.2.1 is now rolling out as an automatic update for sites that support them.

To manually update an installation, download WordPress 4.2.1 or click “Update Now” from the admin Dashboard. 

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Signature Partners With BunnyCMS for Secure Payment Processing

Signature Payments has partnered with adult content management platform BunnyCMS to offer creators secure payment processing.

Sexologist Dr. Susan Block Files Motion in Meta Lawsuit

Sexologist Dr. Susan Block has reported she has filed a Motion to Vacate with a California court after an arbitrator threw out her case against Meta in June.

JustFor.fans Launches BlueSky Autoposting Feature

JustFor.fans has launched a new BlueSky autoposting feature that shares JFF posts on the social media platform.

Pineapple Support Introduces 'Sacred Rage' Support Group for Performers, Creators

Pineapple Support will host a free online support group for performers and creators, designed for individuals struggling with intense emotions and the pain often hidden behind their anger.

FSC: Kansas Attorneys Seeking Plaintiffs to Sue Adult Companies Over Age Verification

Free Speech Coalition (FSC) has released a statement warning that a personal injury law firm in Kansas is soliciting plaintiffs to sue adult companies under the state's age verification law.

Ukrainian Parliament Registers Bill to Decriminalize Porn

Ukraine's parliament, the Verkhovna Rada, registered a bill today to decriminalize the creation and distribution of pornography.

Cherie DeVille Guests on 'Sex Tales' Podcast

2023 XBIZ Performer of the Year Cherie DeVille is the latest guest on the "Sex Tales" podcast, hosted by Melissa Stratton and Vanniall, streaming on the company’s “Camming Life” YouTube channel.

Niki Media Acquires BritSexCash

Production studio Niki Media BV has acquired affiliate program BritSexCash.

FSC Warns of Nude Photography Site Falsely Claiming Affiliation With Organization

Free Speech Coalition (FSC) published a statement Friday warning of a nude art photography website fraudulently claiming to be associated with the industry trade organization.

MojoHost Reaffirms Commitment to Adult Industry Amid Project 2025 Implications

In the wake of Tuesday’s election and concerns about Project 2025’s potential ramifications, MojoHost President Brad Mitchell has released a statement affirming its commitment to the adult industry.

Show More