Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Wildfire smoke is getting worse for everyone, especially disadvantaged groups

    June 10, 2023

    Luxury goods: Europe’s joke on the world

    June 10, 2023

    Trump indictment details plot to hide sensitive documents | Donald Trump News

    June 10, 2023
    Facebook Twitter Instagram
    Facebook Twitter Instagram
    EasyDailyCrypto – Today Crypto | Bitcoin | Global World News
    Button
    • Home
    • Features
      • Contact
    • Crypto
    • Politics

      Kevin McCarthy And Jim Jordan Plot To Illegally Interfere In Trump’s Trial

      June 10, 2023

      Trump Melts Down And Claims His Indictment Is A Cover Up For Biden Stealing Money

      June 10, 2023

      Bombshell Indictment Reveals Trump Asked His Lawyer To Destroy Classified Documents

      June 10, 2023

      A Female Trump Family Member Helped Him Hide Documents From The DOJ

      June 10, 2023

      Jack Smith Sends A Crushing Message To Trump’s GOP Defenders

      June 10, 2023
    • Technology
      1. Crypto
      2. Politics
      3. Business
      4. Lifestyle
      5. View All

      Shiba Inu Millionaire Numbers Decline Rapidly As SHIB Price Suffers

      June 10, 2023

      OKX Completes 20th Quarterly Burn: Here’s How Much OKB Was Destroyed

      June 10, 2023

      3 Transitions Ethereum Needs To Make: Vitalik Buterin

      June 10, 2023

      Crypto.com Shuts Down US Institutional Exchange Amid Regulatory Concerns

      June 10, 2023

      Kevin McCarthy And Jim Jordan Plot To Illegally Interfere In Trump’s Trial

      June 10, 2023

      Trump Melts Down And Claims His Indictment Is A Cover Up For Biden Stealing Money

      June 10, 2023

      Bombshell Indictment Reveals Trump Asked His Lawyer To Destroy Classified Documents

      June 10, 2023

      A Female Trump Family Member Helped Him Hide Documents From The DOJ

      June 10, 2023

      Luxury goods: Europe’s joke on the world

      June 10, 2023

      Car and battery makers to miss out on benefits from Atlantic declaration

      June 10, 2023

      Boris Johnson calls time on parliament ‘for now’ — and that spells trouble for Sunak

      June 10, 2023

      Donald Trump charged with 37 counts in classified documents case

      June 10, 2023

      Easy Ways to Add Retinol to Your Routine

      June 8, 2023

      The 4 Best Clean Lubes

      June 6, 2023

      Jeanine Lobell’s Glowy, Chic Makeup (and Skin) Tutorial

      June 6, 2023

      It’s a Summer of Sea Minerals for Skin, Flickering Candles, and a New French Brush

      June 6, 2023

      Wildfire smoke is getting worse for everyone, especially disadvantaged groups

      June 10, 2023

      Google Chrome’s password manager adds biometric unlocking on desktop

      June 10, 2023

      Bing’s chatbot now lets you ask questions with your voice on desktop

      June 10, 2023

      How to import your passwords to Chrome and the Google Password Manager

      June 10, 2023
    EasyDailyCrypto – Today Crypto | Bitcoin | Global World News
    Beranda » WordPress Hit With Multiple Vulnerabilities In Versions Prior To 6.0.3
    Webmaster

    WordPress Hit With Multiple Vulnerabilities In Versions Prior To 6.0.3

    EASYDAILYCRYPTO NEWSBy EASYDAILYCRYPTO NEWSDecember 5, 2022No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    WordPress published a security release to address multiple vulnerabilities discovered in versions of WordPress prior to 6.0.3. WordPress also updated all versions since WordPress 3.7.

    Cross Site Scripting (XSS) Vulnerability

    The U.S. Government National Vulnerability Database published warnings of multiple vulnerabilities affecting WordPress.

    There are multiple kinds of vulnerabilities affecting WordPress, including a type known as a Cross Site Scripting, often referred to as XSS.

    A cross site scripting vulnerability typically arises when a web application like WordPress doesn’t properly check (sanitize) what is input into a form or uploaded through an upload input.

    An attacker can send a malicious script to a user who visits the site which then executes the malicious script, thereupon providing sensitive information or cookies containing user credentials to the attacker.

    Another vulnerability discovered is called a Stored XSS, which is generally considered to be worse than a regular XSS attack.

    With a stored XSS attack, the malicious script is stored on the website itself and is executed when a user or logged-in user visits the website.

    A third kind vulnerability discovered is called a Cross-Site Request Forgery (CSRF).

    The non-profit Open Web Application Security Project (OWASP) security website describes this kind of vulnerability:

    “Cross-Site Request Forgery (CSRF) is an attack that forces an end user to execute unwanted actions on a web application in which they’re currently authenticated.

    With a little help of social engineering (such as sending a link via email or chat), an attacker may trick the users of a web application into executing actions of the attacker’s choosing.

    If the victim is a normal user, a successful CSRF attack can force the user to perform state changing requests like transferring funds, changing their email address, and so forth.

    If the victim is an administrative account, CSRF can compromise the entire web application.”

    These are the vulnerabilities discovered:

    1. Stored XSS via wp-mail.php (post by email)
    2. Open redirect in `wp_nonce_ays`
    3. Sender’s email address is exposed in wp-mail.php
    4. Media Library – Reflected XSS via SQLi
    5. Cross-Site Request Forgery (CSRF) in wp-trackback.php
    6. Stored XSS via the Customizer
    7. Revert shared user instances introduced in 50790
    8. Stored XSS in WordPress Core via Comment Editing
    9. Data exposure via the REST Terms/Tags Endpoint
    10. Content from multipart emails leaked
    11. SQL Injection due to improper sanitization in `WP_Date_Query`
    12. RSS Widget: Stored XSS issue
    13. Stored XSS in the search block
    14. Feature Image Block: XSS issue
    15. RSS Block: Stored XSS issue
    16. Fix widget block XSS

    Recommended Action

    WordPress recommended that all users update their websites immediately.

    The official WordPress announcement stated:

    “This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately.

    All versions since WordPress 3.7 have also been updated.”

    Read the official WordPress announcement here:

    WordPress 6.0.3 Security Release

    Read the National Vulnerability Database entries for these vulnerabilities:

    CVE-2022-43504

    CVE-2022-43500

    CVE-2022-43497

    Featured image by Shutterstock/Asier Romero

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    EASYDAILYCRYPTO NEWS
    • Website

    Daily update exclusive News about the latest Crypto, Bitcoin, Ethereum, Blockchain, NFTs, Altcoin, Trendings News with the latest Global World News today

    Related Posts

    Google’s Head of Ads Safety Talks Clicks and Compliance [Podcast]

    June 10, 2023

    An Interview w/ Alejandro Borgia, Director of Ad Safety

    June 10, 2023

    Bing AI Voice Chat Comes to Desktop

    June 10, 2023

    Leave A Reply Cancel Reply

    Advertisement
    Our Picks

    Kim Kardashian’s Cryptocurrency Lawsuit Progresses

    June 7, 2023

    Red Sox rally late to beat Guardians, end skid

    June 7, 2023

    How Blogging Can Boost Sales and Revenue

    June 6, 2023

    Blow For Metaverse, SEC Classifies SAND And MANA As Securities

    June 6, 2023
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Technology

    Wildfire smoke is getting worse for everyone, especially disadvantaged groups

    By EASYDAILYCRYPTO NEWSJune 10, 202300 Views

    Americans are breathing in a lot more wildfire smoke today than they did 10 years…

    Luxury goods: Europe’s joke on the world

    June 10, 2023

    Trump indictment details plot to hide sensitive documents | Donald Trump News

    June 10, 2023

    Kevin McCarthy And Jim Jordan Plot To Illegally Interfere In Trump’s Trial

    June 10, 2023

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Update Breaking Crypto News about the latest Crypto daily, Ethereum, Blockchain, NFTs, Altcoin, Trends and Happenings including the latest World News. Exclusive crypto coin news in Easy Daily Crypto.

    Email Us: [email protected]
    Contact: +62-822-7359-8787

    Our Picks

    Wildfire smoke is getting worse for everyone, especially disadvantaged groups

    June 10, 2023

    Luxury goods: Europe’s joke on the world

    June 10, 2023

    Trump indictment details plot to hide sensitive documents | Donald Trump News

    June 10, 2023
    Crypto

    Shiba Inu Millionaire Numbers Decline Rapidly As SHIB Price Suffers

    June 10, 2023

    OKX Completes 20th Quarterly Burn: Here’s How Much OKB Was Destroyed

    June 10, 2023

    3 Transitions Ethereum Needs To Make: Vitalik Buterin

    June 10, 2023
    Facebook Twitter Instagram Pinterest
    • Politics
    • Business
    • Crypto
    • Technology
    © 2023 All Right Reserved. Designed by EasyDailyCrypto.com.

    Type above and press Enter to search. Press Esc to cancel.