Wordpress XSS Vulnerability (CVE-2015-3438)
Wordpress XSS Vulnerability (CVE-2015-3438)
Release date:
Updated on:
Affected Systems:
WordPress <4.1.2
Description:
CVE (CAN) ID: CVE-2015-3438
WordPress is a blog platform developed in PHP.
Previous versions of WordPress 4.1.2 have multiple cross-site scripting vulnerabilities in implementation. When using MySQL in non-strict mode, remote attackers can use 4 bytes of UTF-8 characters or reach invalid characters at the database layer, attackers can exploit this vulnerability to inject arbitrary Web scripts or HTML.
<* Source: WordPress
Link: http://www.securityfocus.com/archive/1/535448
*>
Suggestion:
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://wordpress.org/news/2015/04/wordpress-4-1-2/
Https://wordpress.org/news/2015/04/wordpress-4-2-1/
This article permanently updates the link address: