Skip to main content

Your WordPress site could be vulnerable to attack, update it right away

wordpress version released to fix six serious vulnerabilities wordpressheader
Shutterstock
We all have to deal with security patches and updates that try to keep our systems safe from the ever-increasing levels of cybercrime. If you’re a webmaster, then you have at least one more system than most other people that you need to keep up to date, specifically software that runs your website.

Most recently, one of the most popular web publishing systems around, WordPress, suffered some serious vulnerabilities and its developers published a new version to address them. Consider this a public service announcement — if you’re running WordPress, then you want to upgrade to version 4.7.3 immediately, WeLiveSecurity reports.

Recommended Videos

The six vulnerabilities that researchers identified are as follows:

  • Cross-site scripting (XSS) via media file metadata.
  • Control characters can trick redirect URL validation.
  • Unintended files can be deleted by administrators using the plugin deletion functionality.
  • Cross-site scripting (XSS) via video URL in YouTube embeds.
  • Cross-site scripting (XSS) via taxonomy term names.
  • Cross-site request forgery (CSRF) in Press This leading to excessive use of server resources.

Fortunately, the researchers first privately let the WordPress team know of the vulnerabilities early, allowing the development and rollout of a fix before the vulnerabilities were publicly disclosed. That fix is available now for all self-hosted WordPress sites and if your site is set to automatically update, then you might already have received it.

If your site isn’t set to automatically update, then you’ll want to back it up first. If you have a staging site, then you will want to test there first to make sure nothing breaks when the update is applied. Then, just go to the WordPress admin panel, select Dashboard > Updates, and follow the instructions. While you’re at it, you can check to see if any of your WordPress plugins need updating and get them current as well. Plugin vulnerabilities can be just as damaging as those in the core WordPress system.

If you’re running a site on WordPress.com, which is administered by Automattic, then your site will already have been updated and these vulnerabilities, at least, will have been patched. If not, then your job of webmaster just got another important task that you will likely want to check off sooner rather than later.

Mark Coppock
Mark Coppock is a Freelance Writer at Digital Trends covering primarily laptop and other computing technologies. He has…
Microsoft warns that the latest Windows 11 update may crash PC games now
Gaming PC on a desk.

Microsoft has once again temporarily halted the rollout of its latest major Windows 11 update, also known as 24H2. This time it is for systems running select Ubisoft games following widespread user reports of crashes and performance issues. The affected titles include Assassin's Creed Valhalla, Assassin's Creed Origins, Assassin's Creed Odyssey, Star Wars Outlaws, and Avatar: Frontiers of Pandora.

Common complaints include black screens, freezing, and unresponsiveness during gameplay or while loading these titles. "I just bought a new gaming laptop with RTX 4080, Intel i9 14900hx. I can't play the game (Origins) even for 5 minutes because it crashes to a black screen, with audio, and the only way to close it is from task manager. Impossible to play," one user shared on Reddit. Others reported similar frustrations, citing the persistent error “NTDLL.dll” that renders their games unplayable.

Read more
Microsoft Outlook and Teams are down — and might be for a while
Microsoft Outlook app landing page.

As reported by Deadline, over 5,000 people have reported issues with different Microsoft 365 apps since around 8 a.m. ET this morning. The outage is affecting worldwide usage of email and calendar services associated with Exchange, Outlook, and Teams.

https://twitter.com/MSFT365Status/status/1860973220662280356

Read more
Runway can now mimic everything from 35mm disposable cameras to ’80s sci-fi
Images showing Runway Frames.

AI startup Runway, makers of the popular Gen-3 Alpha image generator, debuted a new foundational model that "excels at maintaining stylistic consistency while allowing for broad creative exploration," per the company.

The new model is called Frames, and it offers users the ability to generate images on a wide variety of subjects while strictly adhering to a consistent visual style and aesthetic. Whether it's mimicking '80s camp films like Flash Gordon and Xanadu, aping the format of '90s-era 35mm disposable cameras or retro anime, generating sweeping landscapes or carefully composed still-life shots, Frames sticks to the artistic style the user dictates.

Read more