WordPress 3.9.2 released to address security issue.

If you are using WordPress open source for your blog or company website. You need to install the latest released v.3.9.2 to patch the recent denial of service issue in PHP’s XML processing.

We had some bandwidth issue for days due to XMLRPC traffic coming to our network of websites. I’ve asked our ISP to block it for the time being and even use a plugin to Disable it.

Here’s the summary from WordPress.org website:

  • Fixes a possible denial of service issue in PHP’s XML processing, reported by Nir Goldshlager of the Salesforce.com Product Security Team. Fixed by Michael Adams and Andrew Nacin of the WordPress security team and David Rothstein of the Drupal security team.
  • Fixes a possible but unlikely code execution when processing widgets (WordPress is not affected by default), discovered by Alex Concha of the WordPress security team.
  • Prevents information disclosure via XML entity attacks in the external GetID3 library, reported by Ivan Novikov of ONSec.
  • Adds protections against brute attacks against CSRF tokens, reported by David Tomaschik of the Google Security Team.
  • Contains some additional security hardening, like preventing cross-site scripting that could be triggered only by administrators.

List of Files Revised:

readme.html
wp-admin/about.php
wp-includes/ID3/getid3.lib.php
wp-includes/class-IXR.php
wp-includes/class-wp-customize-widgets.php
wp-includes/compat.php
wp-includes/pluggable.php
wp-includes/version.php
wp-login.php

 

 


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Founder & CEO, EM @QUE.COM

Founder, QUE.COM Artificial Intelligence and Machine Learning. Founder, Yehey.com a Shout for Joy! MAJ.COM Management of Assets and Joint Ventures. More at KING.NET Ideas to Life | Network of Innovation

kingdotnet has 2798 posts and counting.See all posts by kingdotnet

4 thoughts on “WordPress 3.9.2 released to address security issue.

    • August 7, 2014 at 2:35 am
      Permalink

      I blocked XMLRPC using .httaccess file, and use a plugin to disable to all sites.

      Reply
      • July 21, 2026 at 11:03 pm
        Permalink

        Hi KING.NET, thank you for sharing your approach! Blocking XMLRPC via .htaccess and using a plugin is a solid security practice. We appreciate the practical tip for our readers. If you have any other security insights or topics you would like us to explore, feel free to share. Thanks for being part of the QUE.com community!

    • July 27, 2026 at 5:03 am
      Permalink

      Thank you for reading and taking the time to comment, FairfaxCity.com (@Fairfax)! We value your engagement and always welcome feedback from our community. Feel free to explore more articles on QUE.com and join the conversation.

      Reply

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading