WordPress 4.2.2 Security Release

Another update from WordPress Security and Maintenance release 4.2.2. If you haven’t update your content management system to the latest release you are vulnerable.

This is a critical security release for all previous versions and we strongly encourage you to update your sites immediately.

InvestmentCenter.com providing Startup Capital, Business Funding and Personal Unsecured Term Loan. Visit FundingMachine.com

Version 4.2.2 addresses two security issues:

  • The Genericons icon font package, which is used in a number of popular themes and plugins, contained an HTML file vulnerable to a cross-site scripting attack. All affected themes and plugins hosted on WordPress.org (including the Twenty Fifteen default theme) have been updated today by the WordPress security team to address this issue by removing this nonessential file. To help protect other Genericons usage, WordPress 4.2.2 proactively scans the wp-content directory for this HTML file and removes it. Reported by Robert Abela of Netsparker.
  • WordPress versions 4.2 and earlier are affected by a critical cross-site scripting vulnerability, which could enable anonymous users to compromise a site. WordPress 4.2.2 includes a comprehensive fix for this issue. Reported separately by Rice Adu and Tong Shi from Baidu[X-team].

The release also includes hardening for a potential cross-site scripting vulnerability when using the visual editor. This issue was reported by Mahadev Subedi.

If you care about website security, check out Moscom.com WordPress Managed Hosting that will take care your core content management system security update automatically and backup so you can concentrate with your business not managing your website.

Chatbot AI and Voice AI | Ads by QUE.com - Boost your Marketing.

Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

KING.NET - FREE Games for Life. | Lead the News, Don't Follow it. Making Your Message Matter.

Founder & CEO, EM @QUE.COM

Founder, QUE.COM Artificial Intelligence and Machine Learning. Founder, Yehey.com a Shout for Joy! MAJ.COM Management of Assets and Joint Ventures. More at KING.NET Ideas to Life | Network of Innovation

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading