Advisory: Security Advisory: XSS Vulnerability Affecting Multiple WordPress Plug

Posted in: Newsmag
Post count: 9544

FYI: some of these have been patched; not all have.

Multiple WordPress Plugins are vulnerable to Cross-site Scripting (XSS) due to the misuse of the add_query_arg() and remove_query_arg() functions. These are popular functions used by developers to modify and add query strings to URLs within WordPress.

The official WordPress Official Documentation (Codex) for these functions was not very clear and misled many plugin developers to use them in an insecure way. The developers assumed that these functions would escape the user input for them, when it does not. This simple detail, caused many of the most popular plugins to be vulnerable to XSS.

SEE:

https://blog.sucuri.net/2015/04/security-advisory-xss-vulnerability-affecting-multiple-wordpress-plugins.html?utm_campaign=Security%20Advisory&utm_content=14467015&utm_medium=social&utm_source=facebook

YOU CAN SCAN YOUR SITE FREE
https://sitecheck.sucuri.net/

Viewing 1 post (of 1 total)
The forum ‘Newsmag’ is closed to new topics and replies.