Friday, July 24, 2026

WordPress Stored XSS Vulnerability – Update Now


WordPress has announced a security update to fix two vulnerabilities that could provide attackers the opportunity to perform a complete site takeover. Of the two vulnerabilities, the most serious one involves the Stored XSS vulnerability.

WordPress Stores Cross-Site Scripting (XSS) Vulnerability

The WordPress XSS vulnerability was discovered by the WordPress security team in core WordPress files.

Stored XSS vulnerabilities are vulnerabilities that allow attackers to upload scripts directly to a WordPress site.

The location of such vulnerabilities is usually anywhere a WordPress site allows input, such as submitting a post or a contact form.

Usually, these input forms are protected by so-called sanitization. Sanitization is simply the process of making an input accept only certain types of input (such as text) and reject (filter out) other types of input (such as JavaScript files).

According to Wordfencethe affected WordPress files did perform a cleanup to disallow uploading malicious files.

However, the order in which cleanups occur sets the circumstances in which cleanups can be bypassed.

Wordfence provides insight into the patch that fixes this vulnerability:

“The patched version runs wp_filter_global_styles_post before wp_filter_post_kses, so any potential bypasses are already handled and wp_kses can effectively clean them up.”

The reason an attacker can upload a script is usually because of an error in how the file is encoded.

When a website user with admin rights accesses the exploited website, the uploaded malicious JavaScript file is executed and can perform tasks such as taking over the site, creating new admin-level accounts, and installing backdoors with the user’s admin-level access rights and so on.

A backdoor is a file/code that allows hackers to freely access the backend of a WordPress site with full access.

Prototype Pollution Vulnerability

The second issue found in WordPress is called a prototype pollution vulnerability. This vulnerability is a flaw in the JavaScript (or JavaScript library) of a website.

This second problem is actually the problem of both Prototype Pollution Vulnerabilities.

One is a prototype pollution vulnerability found in the Gutenberg wordpress/url package. This is a module in WordPress that allows WordPress sites to manipulate URLs.

For example, this Gutenberg wordpress/url package provides various functions for query strings and performs sanitization on URL slugs to do things like convert uppercase to lowercase.

The second is a prototype pollution vulnerability in jQuery. This vulnerability has been fixed in jQuery 2.2.3.

Wordfence said they are not aware of any exploitation of this vulnerability, and said the complexity of exploiting this particular vulnerability makes it unlikely to be a problem.

The Wordfence vulnerability analysis concluded that:

“An attacker who is able to successfully execute JavaScript in the victim’s browser could potentially take over the website, but the actual attack is highly sophisticated and may require the installation of a separate vulnerable component.”

How bad is the XSS vulnerability stored by WordPress?

This particular vulnerability requires a user with contributor-level access to have the privilege level required to upload malicious scripts.

Therefore, an additional step is required, which is that contributor-level login credentials must first be obtained before proceeding to the next step of exploiting the stored XSS vulnerability.

While the extra steps may make the vulnerability more difficult to exploit, the only factor between relative security and a full site takeover is the strength and complexity of the contributor’s password.

Update to WordPress 5.9.2

The latest version of WordPress, 5.9.2, fixes two security-related issues and resolves and fixes a bug that could cause error messages for websites using the Twenty Twelve theme.

The WordPress tracking ticket explains the error like this:

“Activating the older default theme and clicking Preview Twenty Twelve gave me an error screen with a grey background and a white notification box that said “The theme you are currently using is not compatible with full site editing . “

The official WordPress announcement recommends that all publishers update their installations to WordPress version 5.9.2.

Some sites may have automatic updates enabled and are currently protected.

But not all sites do, as many require someone with admin-level access to approve the update and initiate it.

Therefore, it is prudent to log into your website and check to see if it is currently using version 5.9.2.

If the site is not using version 5.9.2, the next steps to consider are backing up the site itself and then updating to the latest version.

That said, some people add an extra layer of security by first updating their copy of the site on a staging server and looking at the updated beta version to make sure there are no conflicts with currently installed plugins and themes.

Often, after an important update to WordPress, plugins and themes may release updates to resolve issues.

However, WordPress recommends updating as soon as possible.

Citation

Read the official WordPress.org announcement

WordPress 5.9.2 Security and Maintenance Release

Read the Wordfence explanation of the vulnerability

WordPress 5.9.2 Security Update Fixes XSS and Prototype Pollution Vulnerabilities

WordPress 5.9.2 Official Version Summary

WordPress version 5.9.2

Check the WordPress bug fixing documentation

Live preview button display issue

Learn more about WordPress Gutenberg URL Pack

Gutenberg wordpress/url package





Source link

Related articles

Most Popular Baby Names 2024: Top Picks

Join us as we explore the captivating world of the most popular baby names for 2024! Which name will you choose...

Most Popular Baby Names 2024: Top Picks

Join us as we explore the captivating world of the most popular baby names for 2024! Which name will you choose...

How to Settle a Colic Baby: Proven Tips

Eager to discover effective ways to calm your colicky baby? From soothing techniques to critical consultation cues, let's explore what...

What Is Colic in Babies: Key Facts Revealed

Understanding what colic in babies truly entails can be a challenge for many parents. As the evening wears on, and the baby's cries reach a crescendo, an urgent question looms in the air: what now?

The 7 Best Ways to Gain Popularity

Online searches are often not the starting point...
spot_imgspot_img