Wednesday, January 22, 2025
HomeWordpressWordPress Update 4.9.2 - Fix for XSS Vulnerability and 21 Other Bugs

WordPress Update 4.9.2 – Fix for XSS Vulnerability and 21 Other Bugs

Published on

SIEM as a Service

Follow Us on Google News

New WordPress update (4.9.2) released yesterday covering the fix for XSS vulnerability and 21 other bugs. The Vulnerability resides with the Flash fallback files in MediaElement plugin. It impacts all the WordPress version since WordPress 3.7.

Flash Fallback is a media element with WordPress library and now it has been removed from WordPress, also MediaElement released a new version of the plugin that contains the bug fix.

Also, the update includes other 21 bug fixes, you can refer the Codex page for all the issues fixed with WordPress update (4.9.2).

Also Read Most Important Considerations Check to Setup Your WordPress Security

XSS is a very commonly exploited vulnerability type which is very widely spread and easily detectable.An attacker can inject untrusted snippets of JavaScript into your application without validation. This JavaScript is then executed by the victim who is visiting the target site.Read More about XSS

Mitigations

WordPress update (4.9.2) released with the security patches users are recommended to update their sites immediately.

WordPress Update

WordPress update (4.9.2) contains 21 maintenance fixes to the 4.9.1 release series. Updates are simple Dashboard >> Updates >> Update Now.

It is always a good idea to backup your WordPress before proceeding with the update, if there are any issues, you can restore your website.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

PoC Exploit Released for TP-Link Code Execution Vulnerability(CVE-2024-54887)

A security researcher, exploring reverse engineering and exploit development, has successfully identified a critical...

Brave Browser Vulnerability Allows Malicious Website Appears as Trusted One

A security vulnerability has been identified in Brave Browser, potentially allowing malicious websites to...

Beware! Fake SBI Reward APK Attacking Users to Deliver Android Malware

A recent phishing campaign has targeted customers of SBI Bank through a deceptive message...

Gootloader Malware Employs Blackhat SEO Techniques To Attack Victims

The Gootloader malware family employs sophisticated social engineering tactics to infiltrate computers.By leveraging...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Credit Card Skimmer Hits WordPress Checkout Pages, Stealing Payment Data

Researchers analyzed a new stealthy credit card skimmer that targets WordPress checkout pages by...

New WordPress Plugin That Weaponizes Legit Sites To Steal Customer Payment Data

Cybercriminals have developed PhishWP, a malicious WordPress plugin, to facilitate sophisticated phishing attacks, which...

200,000 WordPress Sites Exposed to Cyber Attack, Following Plugin Vulnerability

A critical security vulnerability has been discovered in the popular WordPress plugin Anti-Spam by CleanTalk,...