Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
No Result
View All Result
Home Uncategorized

WordPress releases version 4.2.2 update to fix vulnerability

byCustoms Today Report
11/05/2015
in Uncategorized
Share on FacebookShare on Twitter

YDNEY: David Dede from Sucuri security research company has claimed that any WordPress theme or plugin that runs a genericons package is at risk. Dede adds that the one of the default themes for WordPress, TwentyFifteen, as well as the JetPack plugin, use the genericons icon fonts package.

The vulnerability can allow attackers to hack into any WordPress website using the default theme and plugin if the administrator accidentally clicks on a malicious link. The genericons package comes with an insecure file that makes the site open to cross-site scripting vulnerability.

You might also like

Pakistan to get $3b loan from Islamic Trade Financing Corporation

20/10/2024

Lahore I&I & Enforcement anti-smuggling operations achieve record success in early FY 2024-25

10/09/2024

The firm on Thursday released version 4.2.2 update which is basically a security and maintenance release targeted to fix the vulnerability. The latest release addresses two security issues including updated genericons used in default themes and plugins that scan the WordPress content directory for the affected (and “nonessential”) example.html file and removes it.

Dede of Sucuri tried to demystify the vulnerability and explains, “The XSS vulnerability is very simple to exploit and happens at the Document Object Model (DOM) level. DOM-Based XSS is an XSS attack wherein the attack payload is executed as a result of modifying the Document Object Model (DOM) “environment” in the victim’s browser used by the original client side script, so that the client side code runs in an “unexpected” manner. That is, the page itself (the HTTP response that is) does not change, but the client side code contained in the page executes differently due to the malicious modifications that have occurred in the DOM environment.”

The security firm has also listed few hosts that have also patched the issue recently including GoDaddy, HostPapa, DreamHost, ClickHost, Site5, and SiteGround among others.

 

 

 

 

Tags: WordPress releases version 4.2.2 update to fix vulnerability

Related Stories

Pakistan to get $3b loan from Islamic Trade Financing Corporation

byCT Report
20/10/2024

ISLAMABAD: Islamic Trade Financing Corporation (ITFC) to provide Pakistan with a $3 billion loan, according to an official statement released...

Lahore I&I & Enforcement anti-smuggling operations achieve record success in early FY 2024-25

byCT Report
10/09/2024

LAHORE:  Regional Directorate of Customs Intelligence & Investigation has demonstrated exceptional performance in the first two months of the fiscal...

ICCI and CDA to join hands for tree plantation drive in Capital

byQaisar Mansoor
09/08/2023

ISLAMABAD: Islamabad Chamber of Commerce and Industry (ICCI) in collaboration with the Capital Development Authority (CDA) would jointly launch a...

Customs Officials Yawar Abbas & Tariq Mehmood kidnapped in Karachi

byCT Report
08/07/2023

KARACHI: Customs Intelligence Officer Yawar Abbas and Customs Preventive Officer Tariq Mehmood who were working against smuggling were kidnapped by...

Next Post

First Dartmoor stone circle discovered in more than a century

  • Terms and Conditions
  • Disclaimer

© 2011 Customs Today -World's first newspaper on customs. Customs Today.

No Result
View All Result
  • Transfers and Postings
  • Latest News
  • Karachi
  • Islamabad
  • Lahore
  • National
  • Chambers & Associations
  • Business
  • About Us

© 2011 Customs Today -World's first newspaper on customs. Customs Today.