WordPress 5.2.4 Released with the Fix for 6 Security Vulnerabilities

WordPress 5.2.4 released for public use from today, WordPress is the most popular content management system used by several websites around the world.

According to the stats report, WordPress shares 34% of the websites on the Internet. It holds 60% of the CMS market share.

WordPress 5.2.4

Today WordPress released 5.2.4, which mainly contains the security fixes. According to WordPress, this is a security update before WordPress major updates. WordPress 5.3 will be the final update in 2019 and that is scheduled on 12 November 2019.

The security update resolves multiple XSS, unauthenticated posts request, cache poison, server-side request forgery, and validation issues.

  • Props to Evan Ricafort for finding an issue where stored XSS (cross-site scripting) could be added via the Customizer.
  • Props to J.D. Grimes who found and disclosed a method of viewing unauthenticated posts.
  • Props to Weston Ruter for finding a way to create a stored XSS to inject Javascript into style tags.
  • Props to David Newman for highlighting a method to poison the cache of JSON GET requests via the Vary: Origin header.
  • Props to Eugene Kolodenker who found a server-side request forgery in the way that URLs are validated.
  • Props to Ben Bidner of the WordPress Security Team who discovered issues related to referrer validation in the admin.

Administrators can install the update automatically from the Dashboards itself or alternatievely you can download the WordPress.

Dashboard → Updates and click Update Now.

It is always recommended to backup the database before pushing updates.

You can follow us on LinkedinTwitterFacebook for daily Cyber Security and hacking news updates.

Also Read: Cyber Security Firm “Sophos” Sold for $3.9 Billion in Cash To Thoma Bravo

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago