WordPress Calls for Urgent Update Following Resolution of 11 Security Flaws

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

WordPress Releases Security Update 7.1.1

WordPress has unveiled version 7.1.1, a crucial security and maintenance update designed to rectify 11 vulnerabilities within the extensively utilized content management platform.

In light of these findings, website proprietors and administrators are strongly encouraged to implement the update without delay to mitigate the risk of potential threats, including cross-site scripting, authorization bypass, information disclosure, path traversal, and content manipulation.

The 7.1.1 iteration encompasses 17 rectifications pertaining to WordPress Core alongside 19 amendments for the Block Editor.

Websites configured for automatic background updates are expected to receive this patch seamlessly.

For those overseeing manual updates, the release can be installed via the WordPress Dashboard by navigating to Updates and selecting the ‘Update Now’ option.

This update addresses several persistent cross-site scripting (XSS) vulnerabilities. A notable concern resides within the wpautop() function, with the potential for an unauthenticated visitor to embed harmful scripts into content pending comment approval.

Should such a comment be sanctioned and subsequently viewed by another user, the embedded code might execute within that individual’s browser.

WordPress Stresses the Importance of Updating

Another identified XSS vulnerability impacts certain themes with custom header support. WordPress has also addressed an HTML API security flaw within the set_modifiable_text() function, where specifically crafted abrupt-closing sequences could allow an assailant to escape the confines of a comment context.

Moreover, several deficiencies were found that could possibly facilitate unauthorized actions or reveal sensitive data.

A maliciously crafted URL could enable the automatic installation and previewing of an inactive theme from WordPress.org.

While this issue does not incontrovertibly indicate that arbitrary theme installation from an attacker-controlled source is feasible, it could be manipulated to alter site behaviors or present administrators with unwanted theme previews.

The release further mitigates an authenticated path traversal vulnerability reported in the WP REST Templates Controller by Anthropic.

Path traversal vulnerabilities can potentially empower authenticated users to access or manipulate files and resources lying outside the designated directory path, contingent on the specific affected component and configuration employed.

Another enhancement prevents users with Contributor privileges or higher from overwriting arbitrary posts.

WordPress has also fortified missing authorization checks that could otherwise expose drafts or pending post slugs to contributors and unearth the title of a private parent post through attachment metadata.

In addition, the XML-RPC interface has undergone a security rectification following revelations that it could be exploited to publish customize_changeset posts while circumventing checks for the edit_css capability.

Historically, XML-RPC has been a focal point for WordPress attackers, given its potential to enable remote publishing and administrative functionalities.

Furthermore, WordPress resolved a concern whereby any authenticated user could reparent comments, including internal notes.

a close up of a typewriter with the word wordpress printed on it

In environments with multiple users, this limitation could adversely affect moderation workflows, comment organization, and the integrity of editorial records.

Security researchers, including Rafie Muhammad, Jeremy Felt, Paulos Yibelo, pwn.ai, Jesse McNeil, Anthropic, Ben Bidner, HDWSec, hermanhms, and viridis, responsibly reported these vulnerabilities.

The organization has stated that the security modifications are being backported, where warranted, to supported security branches, currently encompassing versions up to 4.7.

However, active support is exclusively extended to the latest WordPress release, thus rendering version 7.1.1 the preferred choice for production deployments.

Source link: Cybersecuritynews.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading