Critical XSS 0-Day Disclosed in WordPress

  • Sunday, 26th April, 2015
  • 12:57pm
This is a Public Service Announcement, it does not mean you are affected. It is being shared to help bring awareness to a vulnerability that affects multiple WordPress installs. 


This morning a 
critical 0-Day Cross-Site Scripting (XSS) vulnerability was released in WordPress. This vulnerability targets the way that the WordPress application handles comments. This means if you use the WordPress commenting system you're susceptible to attack. 


This was released by 
Klikki via his blog
« Back