Release date:
Updated on:
Affected Systems:
WordPress <3.8.2
Description:
--------------------------------------------------------------------------------
WordPress is a blog platform developed using the PHP language. You can set up your own website on servers that support PHP and MySQL databases.
WordPress versions earlier than 3.8.2 have multiple implementation vulnerabilities, which can be exploited to bypass certain security restrictions and execute cross-site scripts.
These vulnerabilities are caused by errors in cookie monitoring hash value verification, errors in "publish_post" function verification, and incorrect Plupload-related input, these errors can cause unauthorized access, restricted operations, and arbitrary HTML and script code execution.
<* Source: Jon Cave
Szymon Gruszecki
Link: http://secunia.com/advisories/57769/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://wordpress.org/
Http://wordpress.org/news/2014/04/wordpress-3-8-2/