bazarasfen.blogg.se

Astra wordpress 5.9
Astra wordpress 5.9




astra wordpress 5.9

Contributor+ Stored Cross Site Scripting VulnerabilityĪffected Versions: WordPress Core 5.9.0-5.9.1ĬVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

#ASTRA WORDPRESS 5.9 UPDATE#

Wordfence free users will receive these rules after 30 days on April 10, 2022.Įven if you are protected by the Wordfence firewall, we encourage you to update WordPress core on all your sites at your earliest convenience, if they have not already been automatically updated.

astra wordpress 5.9

These rules have been deployed to Wordfence Premium, Wordfence Care, and Wordfence Response users. We have released two new firewall rules to protect against the vulnerabilities patched in WordPress 5.9.2. Vulnerability AnalysisĪs with all WordPress core releases containing security fixes, the Wordfence Threat Intelligence team has analyzed the update in detail to ensure our customers remain secure.

astra wordpress 5.9

All versions of WordPress since WordPress 3.7 have also been updated with the fix for these vulnerabilities. The two medium-severity vulnerabilities impact WordPress versions earlier than 5.9.2 and potentially allow attackers to execute arbitrary JavaScript in a user’s session if they can trick that user into clicking a link, though there are no known practical exploits for these two vulnerabilities affecting WordPress. The Wordfence Threat Intelligence team was able to create a Proof of Concept for this vulnerability fairly quickly and released a firewall rule early on March 11, 2022, to protect WordPress sites that have not yet been updated. The high-severity issue affects version 5.9.0 and 5.9.1 and allows contributor-level users and above to insert malicious JavaScript into WordPress posts. Last night, just after 6pm Pacific time, on Thursday March 10, 2022, the WordPress core team released WordPress version 5.9.2, which contains security patches for a high-severity vulnerability as well as two medium-severity issues. WordPress 5.9.2 Security Update Fixes XSS and Prototype Pollution Vulnerabilities






Astra wordpress 5.9