Update Lagi Yukk. Celah XSS 0day WordPress 4.2 pada Fitur Komentar


Status
Not open for further replies.

PusatHosting

Hosting Guru
Kemarin sudah kena ini dan sekarang ada yang baru yaitu XSS 0day pada fitur komentar wordpress. Sudah tersedia patch 4.2.1 Silahkan update.
Info detail dari securi .
**Update 20150427**: A patch has been released and made available by the WordPress Core Team in version 4.2.1 – Please update immediately.

Yes, you’ve read it right: a critical, unpatched 0-day vulnerability affecting WordPress’ comment mechanisms was disclosed earlier today by Klikki Oy.

Who’s affected
If your WordPress site allows users to post comments via the WordPress commenting system, you’re at risk. An attacker could leverage a bug in the way comments are stored in the site’s database to insert malicious scripts on your site, thus potentially allowing them to infect your visitors with malware, inject SEO spam or even insert backdoor in the site’s code if the code runs when in a logged-in administrator browser.

You should definitely disable comments on your site until a patch is made available or leverage a WAF to protect your site and customers.
sumber : https://blog.sucuri.net/2015/04/critical-persistent-xss-0day-in-wordpress.html
 

mustafaramadhan

Hosting Guru
Soal update, wordfence selalu kirim email jika wordpress, theme dan plugin perlu diupdate.
 

dhyhost

Web Hosting Service
The Warrior
Verified Provider
lg bnyk update yak :D
 

atria

Apprentice 1.0
Entah sejak versi berapa, rasa-rasanya wordpress selalu update otomatis kalau ada masalah security.
Tahu-tahu ada email bahwa blog sudah di upgrade ke versi x.x.x
 
Status
Not open for further replies.

Top