Most popular WordPress versions are currently affected. A stored cross-site scripting (XSS) vulnerability available in the recently released WordPress 4.2 and earlier versions can be exploited by an unauthenticated party to run arbitrary code on the server; the security glitch is currently unpatched and proof-of-concept code is publicly available . An attacker taking advantage of the flaw could take control of the targeted website by creating new admin accounts . Aside from the current WordPress versions, build 4.1.2, 4.1.1 and 3.9.3 are also affected. Comment text truncation issue still not fully fixed. Discovered by Jouko Pynnönen , from vulnerability research firm Klikki Oy in Finland , the flaw is similar to the one patched in WordPress 4.1.2, after having been disclosed to the developer by researcher Cedric Van Bockhaven about 14 months ago, on February 23, 2014 . Bockhaven’s approach consisted in introducing a character in the message that truncates the text at a speci
Whaddya know about Business, Real Estate, Investor, Wealth and Entrepreneurship. Managed by Que.com.