WordPress quickly patches second critical vulnerability

It's the second time in a week WordPress had fixed flaws involving malicious comments

WordPress patched a second critical vulnerability in its Web publishing platform on Monday, less than a week after fixing a similar problem.

Administrators are advised to upgrade to WordPress version 4.2.1. Some WordPress sites that are compatible with and use a plugin called Background Update Tester will update automatically.

WordPress is one of the most-used Web publishing platforms. By the company's own estimation, it runs 23 percent of the sites on the Internet, including major publishers such as Time and CNN.

The latest flaw was found by Jouko Pynnönen[cq] of Klikki Oy, a Finish software company. Pynnönen found WordPress was vulnerable to a cross-site scripting flaw if an attacker inserted malicious JavaScript into a comments field. The script runs when someone views the comment, according to an advisory.

Cross-site scripting flaws are among the most dangerous and common Web vulnerabilities, allowing rogue code to run that should be forbidden.

If a WordPress administrator is logged in when the malicious comment is viewed, the attacker can then execute arbitrary code on the server through the plugin and theme editors. It is also then possible to change the administrator's password, create new administrator accounts or manipulate content on a site. The vulnerability can't cause damage from an ordinary reader viewing the comment.

Klikki Oy alleged that WordPress had stopped communicating with it last November when Klikki found a different vulnerability in WordPress. With the latest flaw, Klikki said it had also tried to notify WordPress through the Finnish computer security authority, CERT-FI, and HackerOne, which offers a service for managing vulnerability reports and rewards.

On April 21, WordPress patched a vulnerability similar to the one Pynnönen came across. Cedric Van Bockhaven[cq] found that WordPress was vulnerable to a cross-site scripting attack involving comments due to a MySQL database behavior it allowed.

He found that rogue code could be executed when a person hovered over a malicious script inserted into a comments field. Proof-of-concept code written by Van Bockhaven showed how a new user could be added in the administration panel. The flaw could also be used to download a plugin that runs malicious server-side code, he wrote on his blog.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags securityWordpressExploits / vulnerabilitiesKlikki Oy

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?