Automattic , the company behind the open-source WordPress content management system, began automatically installing a security update to millions of websites yesterday to address a critical vulnerability in the Jetpack WordPress plugin .

Jetpack is a widely used plugin that offers improved security, performance, and website management. It can help with website backups, protection against hacking attacks , and other features like malware scanning, etc.
See also: SpinOk Android malware detected in multiple apps
According to the official WordPress plug-in repository, Jetpack now has over 5 million active installations.
“During an internal security audit, we identified a vulnerability with the API available in Jetpack since version 2.0, released in 2012,” said Jeremy Herve of Automatic.
The new Jetpack 12.1.1 security update began rolling out automatically to WordPress sites using the plugin yesterday and has already been installed on more than 4,130,000 sites using every version of Jetpack since version 2.0.
See also: DogeRAT Trojan mainly targets Android users
This means that most vulnerable websites have already been automatically updated and the rest will soon be patched.
Herve also warned website administrators to check that their sites are secure. He said there is no evidence that this particular Jetpack vulnerability has been abused in attacks, but malicious users will likely try to create exploits to target WordPress sites that have not received the update.

“… Now that the update has been released, it is possible that someone could try to exploit this vulnerability,” Herve said.
“Update your Jetpack version as soon as possible to keep secure . To help you with this process, we've worked closely with the WordPress.org Security Team to release patched versions of every Jetpack version since version 2.0. Most sites have been updated or will soon be automatically updated to a secure version.“.
See also: Mirai botnet: IZ1H9 variant targets IoT devices
This is not the first time that Automattic has rolled out automatic security to fix critical issues in plugins or WordPress installations.
Source: www.bleepingcomputer.com
