Skip to content
CVTF Studios.net Logo CVTF Studios.net Logo CVTF Studios.net Logo
  • Homepage
  • Our Blogs
    • General systems vulnerabilities
      • Apple Engineers Might Quit If Ordered To Unlock iPhone For FBI
      • 15000 compromised servers
      • Crypto-Mining Supply Chain Attack Hits UK Gov’t websites
      • Facebooks Messenger’s app lets people send their location to friends and it defaults to sending a location with all messages
      • Fortinet SSH Backdoor Found In Firewalls
      • Location of UK Mobile Phone Users Could Be Compromised
      • Two critical vulnerabilities in Foxit Reader
    • Linux
      • 8 Reasons to Switch from Windows 10 to Linux
      • How to Use SSH Pipes on Linux
      • WhatsApp found collecting data and phone numbers
      • What is the best Linux Distributions for Hacking and Penetration Testing in 2016
    • MS Windows
      • Windows 10 spying on us all
      • Windows 10 automatically installs without permission complain users
    • WordPress
      • Update of WordPress to 4.8
      • How to find and replace text with one click in your WordPress database
  • Hosting Packages
    • Business Hosting Package
    • Corporate Hosting Package
    • Professional Hosting Package
    • Starter Hosting Package
    • Our web hosting prices
  • Technical Support & Web Programming
    • Bespoke Web Apps
    • Clean virus infected websites
    • Digital Forensics and Cyber Security Services
    • GDPR Compliance Services
    • Internet Streaming Radio
    • Technical Support
  • Shop
    • Cart Page
    • Checkout Page
    • My Account
  • Contact Us
    • Contact Us Form
  • About Us
    • GDPR – Request to access or remove all your personal info
    • Our NewsLetter
    • Our Privacy Policy
    • Terms and conditions of use

WordPress 4.2.1 released new patch

  1. Home
  2. Web Design
  3. Web Security
  4. Word Press
  5. WordPress 4.2.1 released new patch
Previous Next

WordPress 4.2.1 released new patch

WordPress 4.2.1 Released to Patch Comment Exploit Vulnerability

Sarah Gooding April 27, 2015 4
photo credit: Will Montague - cc
photo credit: Will Montague – cc

This morning we reported on an XSS vulnerability in WordPress 4.2, 4.1.2, 4.1.1, and 3.9.3, which allows an attacker to compromise a site via its comments. The security team quickly patched the vulnerability and released 4.2.1 within hours of being notified.

WordPress’ official statement on the security issue:

The WordPress team was made aware of a XSS issue a few hours ago that we will release an update for shortly. It is a core issue, but the number of sites vulnerable is much smaller than you may think because the vast majority of WordPress-powered sites run Akismet, which blocks this attack. When the fix is tested and ready in the coming hours WordPress users will receive an auto-update and should be safe and protected even if they don’t use Akismet.

That auto-update is now being rolled out to sites where updates have not been disabled. If you are unsure of whether or not your site can perform automatic background updates, Gary Pendergast linked to the Background Update Tester plugin in the security release. This is a core-supported plugin that will check your site for background update compatibility and explain any issues.

Since Akismet is active on more than a million websites, the number of affected users that were not protected is much smaller than it might have been otherwise.

WordPress 4.2.1 is a critical security release for a widely publicized vulnerability that you do not want to ignore. Users are advised to update immediately. The background update may already have hit your site. If not, you can update manually by navigating to Dashboard → Updates.

By admin|2016-12-03T00:16:45+00:00April 27th, 2015|Web Design, Web Security, Word Press|0 Comments

Share This Story, Choose Your Platform!

FacebookXRedditLinkedInWhatsAppTelegramTumblrPinterestVkXingEmail

About the Author: admin

Related Posts

Let’s Encrypt Revoking 3 Million TLS Certificates
Let’s Encrypt Revoking 3 Million TLS Certificates
Gallery

Let’s Encrypt Revoking 3 Million TLS Certificates

Crypto-Mining Supply Chain Attack Hits UK Gov’t websites
Crypto-Mining Supply Chain Attack Hits UK Gov’t websites
Gallery

Crypto-Mining Supply Chain Attack Hits UK Gov’t websites

15000 compromised servers
15000 compromised servers
Gallery

15000 compromised servers

Two critical vulnerabilities in Foxit Reader
Two critical vulnerabilities in Foxit Reader
Gallery

Two critical vulnerabilities in Foxit Reader

Update of WordPress to 4.8
Update of WordPress to 4.8
Gallery

Update of WordPress to 4.8

Leave A Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Product Tags

Bespoke Web Apps Bespoke Web Apps prices Business Hosting Packages Clean viruses Corporate Hosting Package GDPR Compliance Services Internet streaming radio station Professional Hosting Package Starter Hosting Package

Product categories

Contact Info

Phone: 07950 838 482

Mobile: 07950 838 482

Email: Email us here

Web: Contact us here

Spam Blocked

13,921 spam blocked by Akismet
Copyright 2007 - 2022 CVTF Studios.net | All Rights Reserved | Powered by CVTF Studios.net
Facebook
Page load link
Go to Top