• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

WordPress 5.1.1 fixes a threatening XSS vulnerability

5352

5.1.1 Fixes XSS Vulnerability Leading to Website Takeovers

WordPress 5.1.1 had recently patched an XSS vulnerability, but the researchers didn't stop probing into the situation, as they found out how devastating the threat was as it would lead an attacker to take over a WordPress site using something as simple as a maliciously crafted comment. Discovered by RIPS Technologies, the flaw is a cross-site request forgery (CSRF) flaw that exists on any site running version 5.1 or earlier with default settings and comments enabled.

The heart of the problem is the measures Wordpress has taken to keep it protected from the CSRF-based takeovers in comments which is not secure. CSRF attacks happen when an attacker hijacks an authenticated user session so that the malicious instructions appear to come from that user’s browser. In the case of the recently patched flaw, the attacker could have lured a WordPress admin to a malicious website thus serving cross-site scripting (XSS) payload.

Even though websites defend themselves from CSRF in many possible ways, the complexity of the task means there are always cracks attackers can slip through.

What could have been a better solution?

The solution is to update WordPress to version 5.1.1, which appeared on 12 March with a fix for this flaw. If auto-updating is not turned on, it’s the usual drill: visit Dashboard > Updates and click Update. To go one step further to keep away from these attacks, Webmasters can disable comments entirely while remembering to log out of WordPress admin before visiting other websites.

Tags:
kishore
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 0 )

No questions available

Related Tutorials in WordPress 5.1.1 fixes a threatening XSS vulnerability

Related Tutorials in WordPress 5.1.1 fixes a threatening XSS vulnerability

How to install Wordpress on opensuse15.1
How to install Wordpress on opensuse15.1
Nov 27, 2019
How to install Wordpress using CentOS Web Panel
How to install Wordpress using CentOS Web Panel
Aug 7, 2017
How to install Wordpress CMS V4.9.6 on Fedora-28
How to install Wordpress CMS V4.9.6 on Fedora-28
Jun 9, 2018
How to install WordPress in Ubuntu 22.04
How to install WordPress in Ubuntu 22.04
Jun 10, 2023
How to install Wordpress CMS 4.9.8 on MX 17
How to install Wordpress CMS 4.9.8 on MX 17
Oct 10, 2018
How to install Wordpress using Nginx
How to install Wordpress using Nginx
Aug 4, 2016
How to Install WordPress CMS on Oracle Linux 8.5
How to Install WordPress CMS on Oracle Linux 8.5
Jun 4, 2022
How to install Wordpress CMS V4.9.6 on Linuxmint-18.03
How to install Wordpress CMS V4.9.6 on Linuxmint-18.03
Jun 23, 2018

Related Forums in WordPress 5.1.1 fixes a threatening XSS vulnerability

Related Forums in WordPress 5.1.1 fixes a threatening XSS vulnerability

Wordpress
owen class=
how to install wordpress with openlitespeed
Feb 27, 2017
Apache
daniel class=
Wordpress Installation : Internal server error
Jun 15, 2018
Wordpress
henry class=
Database is not connecting to Wordpress in linux
Feb 25, 2017

Related News in WordPress 5.1.1 fixes a threatening XSS vulnerability

Related News in WordPress 5.1.1 fixes a threatening XSS vulnerability

CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
Mar 12, 2019
URL Attacks and The Ways to Stay Away from Them!
URL Attacks and The Ways to Stay Away from Them!
Mar 19, 2019
WordPress and Joomla websites infected by new backdoor malware
WordPress and Joomla websites infected by new backdoor malware
May 31, 2019
ATM Skimming Attack With Hijacked ATM Security Camera to Steal User’s PIN
ATM Skimming Attack With Hijacked ATM Security Camera to Steal User’s PIN
Mar 13, 2019
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Sep 7, 2019
Magecart Targets OpenCart Websites Payment Information
Magecart Targets OpenCart Websites Payment Information
May 17, 2019
WordPress 5.1.1 fixes a threatening XSS vulnerability
WordPress 5.1.1 fixes a threatening XSS vulnerability
Mar 22, 2019
Major Security Flaw Found in Cisco Routers
Major Security Flaw Found in Cisco Routers
Oct 2, 2019
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Sebastian ?
How to change non required to required field in SuiteCRM Custom/Default Modules

How to change not required to the required field in SuiteCRM Custom/Default Modules?

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.