WordPress announced a safety publish to location seven safety vulnerabilities affirmative four bug fixes. This safety release, Version 7.1.3, addresses a stored XSS, denial-of-service DoS and five another vulnerabilities of undisclosed severity level. WordPress recommends updating sites immediately.
Seven Vulnerabilities
WordPress names seven vulnerabilities:
- Stored XSS
- DoS issue
- Second-Order SQL injection
- Weakness allowing Author function users to sticky posts
- Unauthenticated disclosure of comments
- Imgur embeds susceptible to XSS
- Forgeable parameters that can guide to act name collision
The authoritative notice does not catalog severity ratings, CVSS scores,describe the vulnerabilities, or recommendation data of whether these vulnerabilities are being exploited in the the wild. However, WordPress recommends updating immediately.
The safety fixes are additionally being backported to older WordPress branches eligible for safety fixes, currently extending through WordPress 4.7, although those backports are motionless in progress. Backports volition container for older branches as they rotate into ready.
Bug Fixes
The four bug fixes contain three comparatively benign issues that logic a mediocre person cognition affirmative one that is critical.
Two of the bug fixes location oEmbed endpoints that come back a 404 message. One is connected to a music promotion phase and the another an eCard wit site. One of the fixes addresses a bug that may logic a website icon depiction in the admin to toolbar develop to gigantic proportions. The fourth can guide to a fatal error that appears bad but likely isn’t that bad.
Critical Flaw Leads To Fatal Error
The fourth is a crucial WordPress bug can create depiction uploads neglect alongside a fatal error on hosts lacking an optional DOM library, leaving location owners unable to upload media. The WordPress ticket for this matter says that the depiction upload procedure stopped completely, so the depiction could not be uploaded. That appears small bad than a complete leaf or location failure.
The missing component is PHP’s DOM expansion (ext-dom), which provides the DOMDocument and DOMXPath classes WordPress was trying to use. The logic this issue may have arisen is that WordPress powerfully recommends the expansion but does not necessitate it.
WordPress 7.0 introduced code that used DOMDocument without archetypal checking whether the expansion existed. On hosts without it, depiction uploads could trigger a fatal error and neglect completely.
The WordPress ticket for this issue rates the bug as critical, but a center committer additionally indicated it was likely rare: the code had been released for 134 days before the archetypal report, which implies that nearly all hosts already provision the DOM expansion and that the crucial flaw is not widespread.
Official notice here.
Featured Image by Shutterstock/Yes058 Montree Nanta