18.gif

Search (advanced search)
Use this Search form before posting, asking or make a new thread.
Tips: Use Quotation mark to search words (eg. "How To Make Money Online")

04-22-2015, 04:46 AM (This post was last modified: 04-22-2015 04:53 AM by kafirbaz12.)
Post: #1
[Security !!!] Wordpress Emergency Plugin Updates
Wordpress Emergency Plugin Updates:

A new version of the Wordpress plugin "" () has been released. A recent hack was found in older versions of this plugin which allows an attacker to perform Cross-site Scripting (XSS) with no authentication required.

"Multiple WordPress Plugins are vulnerable to Cross-site Scripting (XSS) due to the misuse of the add_query_arg() and remove_query_arg() functions. These are popular functions used by developers to modify and add query strings to URLs within WordPress.

The official WordPress Official Documentation (Codex) for these functions was not very clear and misled many plugin developers to use them in an insecure way. The developers assumed that these functions would escape the user input for them, when it does not. This simple detail, caused many of the most popular plugins to be vulnerable to XSS."

To date, this is the list of affected plugins:

Jetpack
WordPress SEO
Google Analytics by Yoast
All In one SEO
Gravity Forms
Multiple Plugins from Easy Digital Downloads
UpdraftPlus
WP-E-Commerce
WPTouch
Download Monitor
Related Posts for WordPress
My Calendar
P3 Profiler
Give
Multiple iThemes products including Builder and Exchange
Broken-Link-Checker
Ninja Forms

See Details here:


https://blog.sucuri.net/2015/04/security...ugins.html
04-22-2015, 05:14 AM
Post: #2
RE: [Security !!!] Wordpress Emergency Plugin Updates
Thanks for the heads up! + rep'd
04-22-2015, 05:17 AM
Post: #3
RE: [Security !!!] Wordpress Emergency Plugin Updates
it is alot of more them ...:D some times boot kali linuks you gana see how meni holes wp got :D
04-22-2015, 05:20 AM
Post: #4
RE: [Security !!!] Wordpress Emergency Plugin Updates
You are right. This one is considered as a major one!

(04-22-2015 05:17 AM)savaskampas Wrote:  it is alot of more them ...:D some times boot kali linuks you gana see how meni holes wp got :D
04-22-2015, 05:38 AM
Post: #5
RE: [Security !!!] Wordpress Emergency Plugin Updates
Gravity forms is a big one, make sure you have version 1.9.5.
21.gif
04-22-2015, 06:30 AM (This post was last modified: 04-22-2015 07:33 AM by kafirbaz12.)
Post: #6
RE: [Security !!!] Wordpress Emergency Plugin Updates
Yes
You have the latest All in One SEO Pack Pro (2.3.6.2) here:

http://bestblackhatforum.com/Thread-GET-...ro-2-3-6-2

(04-22-2015 05:38 AM)storm180 Wrote:  Gravity forms is a big one, make sure you have version 1.9.5.




20.gif