As many as 1 million sites imperiled by dangerous bug in WordPress plugin

As many as a million websites could be imperiled by a critical vulnerability recently discovered in WP-Super-Cache, a WordPress plugin that generates static HTML files from dynamic WordPress blogs.
The persistent cross-site scripting bug allows attackers to insert malicious code into WordPress-published pages that use the extension, according to a blog post published Tuesday by security firm Sucuri. Anyone who relies on the plug in should immediately upgrade to version 1.4.4, which has fixes for that bug and several others.
Sucuri researcher Marc-Alexandre Montpas wrote:
The bug lies in the way WP-Super-Cache displays information stored in the cache file key. In vulnerable versions, user-supplied data was appended to the page contents without being scrubbed clean of any potentially malicious commands.
As many as 1 million sites imperiled by dangerous bug in WordPress plugin
Reviewed by Unknown
on
9:39 PM
Rating:
