WordPress 4.2.1 – Säkerhetsrelease Fixar Zero Day XSS-sårbarhet – Update nu

Bara 3 dagar efter lanseringen av WordPress 4.2 hittade en säkerhetsforskare en Zero day XSS-sårbarhet som påverkar WordPress 4.2, 4.1.2, 4.1.1, 4.1.3 och 3.9.3. This allows an attacker to inject JavaScript into comments and hack your site. WordPress team reagerade snabbt och fixade säkerhetsproblemet i WordPress 4.2.1, och vi rekommenderar starkt att du uppdaterar dina webbplatser omedelbart.

WordPress XSS Security

Jouko Pynnönen, säkerhetsforskare på Klikki Oy, som rapporterade om problemet beskrev det som:

Om det utlöses av en inloggad administratör, under standardinställningar, kan angriparen utnyttja sårbarheten för att köra godtycklig kod på servern via plugin- och theme-editorerna.

Alternativt kan angriparen ändra administratörens password, skapa nya administratörskonton eller göra vad som helst annat som den för närvarande inloggade administratören kan göra på målsystemet.

Denna viss sårbarhet liknar den som rapporterades av Cedric Van Bockhaven och som åtgärdades i säkerhetsreleasen WordPress 4.1.2.

Tyvärr använde de inte korrekt säkerhetsupplysning och publicerade istället utnyttjandet offentligt på sin site. Detta innebär att de som ej uppgraderar sin site kommer att utsättas för allvarliga risker.

Update: Vi har fått veta att de försökte kontakta WordPress säkerhetsteam men misslyckades med att få en snabb response.

Om du inte har inaktiverat automatiska uppdateringar kommer din site att uppdateras automatiskt.

Än en gång rekommenderar vi starkt att du uppdaterar din site till WordPress 4.2.1. Se till att göra en backup av din site innan du updatear.

Avslöjande: Vårt innehåll stöds av våra läsare. Det innebär att om du klickar på några av våra länkar, kan vi tjäna en provision. Se hur WPBeginner finansieras, varför det är viktigt, och hur du kan stödja oss. Här är vår editoriala process.


Editorial Staff at WPBeginner is a team of WordPress experts led by Syed Balkhi with over 16 years of experience in WordPress, Web Hosting, eCommerce, SEO, and Marketing. Started in 2009, WPBeginner is now the largest free WordPress resource site in the industry and is often referred to as the Wikipedia for WordPress.

  2. Rajnish Tyagi says

    hi there,

    my site was 2 times in last week, i am using aws server, for database i am using RDS, but today my database was crashed it take 2 hours for recover, i am using the latest version of wprdress 4.2.2

    please advice me some good security tips


  3. Mike says

    If you have Akismet running there is a good chance that the comments will get flagged as spam so do not check your spam queue.

  4. Bernhard says

    Please take a look at where it is clearly explained how they tried contacting and received no reply SINCE NOVEMBER 2014 (Confirmed vulnerable: WordPress 4.2, 4.1.2, 4.1.1, 3.9.3.):

    ”WordPress has refused all communication attempts about our ongoing security vulnerability cases since November 2014. We have tried to reach them by email, via the national authority (CERT-FI), and via HackerOne. No answer of any kind has been received since November 20, 2014. According to our knowledge, their security response team have also refused to respond to the Finnish communications regulatory authority who has tried to coordinate resolving the issues we have reported, and to staff of HackerOne, which has tried to clarify the status our open bug tickets.”

    If that is correct, disclosing the issue was the only responsible thing to do, and sites are vulnerable not because of the disclosure, but because of the failure on the part of WordPress to address this issue for almost 6 Months.

    I understand that security is a complex issue, but please get your facts straight.

  5. Bilal Bin Amar says

    but after the update, my CMS(wordpress) and my Site have became very slow, under the CMS when i click in the added a plugin this is giving error

  6. William Charles says

    I was auto updated and now it’s asking me to update my database, when I update my data base I get the following error: Catchable fatal error: Object of class WP_Error could not be converted to string in /home/doctorof/public_html/wp-admin/includes/upgrade.php on line 1459

    Any thoughts on how to fix it? Tried the usual methods (turning off plugins, default theme etc).

    • Editorial Staff says

      Please get in touch with your hosting provider. This may be happening due to a database corrupt table. We had it happened with our site List25, and our host was able to fix it right away.


    • kunwar says

      Just visit your admin login page /wp-admin and then press the update database button, this should fix the issue.

  7. pmisun says

    After the auto update applied it totally messed up our instances and we got no server responses. Investigating for 6 hours now, with no positive results. Server is fine, ip providers / isps are fine…

  8. Elaine Maul says

    Thank you for the alert! Although I have automatic updates set, it hadn’t got round to doing it yet for some reason, so I have actioned it myself :)
    Thank you :)

