Successful exploitation of these vulnerabilities can lead to Cross Site Scripting (XSS) and SQL Injection attacks – An immediate upgrade to version 4.2.4 of Wordpress is recommended.
The new version of the popular platform, WordPress 4.2.4, has already been released, patching a number of important security vulnerabilities.
In total, this version addresses 10 bugs, six of which are security-related and can prove quite dangerous if not addressed in time.
More specifically, the updated version fixes three cross-site scripting vulnerabilities and a potential SQL injection vulnerability, which could be exploited to compromise any WordPress website by attackers.
The aforementioned security vulnerabilities were reported by:
- Marc-Alexandre Montpas (researcher at security firm Sucuri)
- Helen Hou Sandi (WordPress Security Team Researcher)
- Netanel Rubin (researcher at Check Point) and
- Ivan Grigorov (member of the bug tracker, HackerOne).
Additionally, researcher Mohamed A. Baste discovered another security issue, which allowed attackers to lock posts indefinitely, preventing future changes from being made to the contents of the affected website.
Finally, security expert Johannes Schmitt of Scrutinizer identified a vulnerability that could under certain circumstances lead to “timing side-channel attacks,” allowing attackers to analyze the time required by cryptographic algorithms to perform their function.

