WordPress 4.2.3 Security Update fixes serious flaw - Update now!
WordPress has just released a new version of its content management system (CMS), WordPress version 4.2.3, to fix a critical security that could be exploited by hackers to take control of websites, affecting the security of millions of sites.
version 4.2.3 resolves a Cross-Site Scripting (XSS) flaw that could allow any user with the editor role to expose a website, WordPress team lead Gary Pendergast said in a blog post yesterday.
Cross-site scripting is actually a vulnerability in the code of Web applications that opens the targeted website to attacks. This vulnerability is one of the most favorite and widely used flaws by cybercriminals.
According to the company, the vulnerability could allow hackers to embed maliciously crafted HTML, JavaScript, Flash, or other code to bypass WordPress's kses protection, thereby tricking users into executing a malicious script on their computer system.
This results in the collection of users' sensitive data, including cookies stored on their systems.
It is currently unknown how websites could be compromised using the flaw, as many details about the vulnerability have not yet been disclosed by the company.
Update WordPress CMS Now!
All versions of WordPress from 4.2.2 and earlier are affected by this flaw, but you shouldn't worry if you have Automatic Security Updates enabled.
However, if you don't have it, you should definitely update your WordPress CMS to WordPress version 4.2.3 as soon as possible.
To update, all you need to do is go to the main WordPress “Dashboard,” then “Updates,” and click “Update Now.”
And you are ready!

