Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

WordPress patches critical XSS vulnerability
iTnews.com.au ^ | on Apr 28, 2015 7:30 AM (AUS) | Juha Saarinen

Posted on 04/28/2015 5:44:46 PM PDT by Utilizer

Commenters could cross-site script.

Wordpress developer Automattic is urging users to urgently update their installations of the company's publishing platform to fix a critical vulnerability that could lead to attackers taking over entire sites.

Jouko Pynnönen of security vendor Klikki.fi discovered a cross-site scripting (XSS) flaw in WordPress that allows commenters to inject Javascript into sites.

When admin users check the comments to moderate them and execute the Javascript they contain attackers can gain full control of the target WordPress site through the plugin and theme editors.

The vulnerability takes advantage of the TEXT data type in the MySQL database that WordPress is built on being limited to 64 kilobytes in size.

A comment longer than 64Kb will be truncated, Pynnönen said, but results in malformed HTML being generated on the WordPress page.

"The attacker can supply any attributes in the allowed HTML tags, in the same way as with the two recently published stored XSS vulnerabilities affecting the WordPress core," he wrote.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: websites; wordpress; xss
Of interest to anyone who uses or works with WordPress, and possibly similar programs just in case.
1 posted on 04/28/2015 5:44:46 PM PDT by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

Well that’s pretty crappy.
Don’t know anything offhand that I use that uses it.
But that doesn’t mean it isn’t there.
I’ll have to look.


2 posted on 04/28/2015 5:53:06 PM PDT by Darksheare (Those who support liberal "Republicans" summarily support every action by same.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Darksheare

Quite a few people do use it, unfortunately. Hope the info helps.


3 posted on 04/28/2015 5:55:58 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Utilizer

I passed it on to a webcomic friend, he might know some people...


4 posted on 04/28/2015 5:57:04 PM PDT by Darksheare (Those who support liberal "Republicans" summarily support every action by same.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Darksheare

Good on ya, mate. Hope word spreads.


5 posted on 04/28/2015 6:03:59 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Utilizer

Will see.


6 posted on 04/28/2015 6:05:10 PM PDT by Darksheare (Those who support liberal "Republicans" summarily support every action by same.)
[ Post Reply | Private Reply | To 5 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson