Release date:
Updated on:
Affected Systems:
WordPress 3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57554
WordPress is a blog platform developed using the PHP language. You can set up your own website on servers that support PHP and MySQL databases.
Wordpress has multiple security vulnerabilities in implementation, which can be exploited by malicious users to execute scripts to insert attacks and leak sensitive information.
1) Some short codes and post content are not properly filtered; 2) Some Plupload-related inputs are not correctly filtered; 3) "pingback. the "sourceUri" parameter value of ping "xmlrpc api method is not properly filtered.
<* Source: Jon Cave
Moxiecode
Gennady Kovshenin
Ryan Dewhurst
Link: http://secunia.com/advisories/51967/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
Currently, the vendor has released a patch to fix this security issue. Please download version 3.5.1 from the vendor's homepage:
Http://wordpress.org/