Lightning Base

Get Started Now

  • Home
  • Tour
  • Pricing
  • Contact
  • About

Patched – Genericons XSS Vulnerability

Wednesday, May 6th, 2015 / Posted In :Security /  By :Chris Piepho / Leave a comment

There is a recently announced XSS vulnerability in the Genericons package, which is included in both JetPack and the TwentyFifteen theme, and likely other addons. This means a huge portion of WordPress installs are potentially at risk.

The Vulnerability

A file called ‘example.html’ exists in the ‘genericons’ directory and is vulnerable to a DOM based XSS attack. If you’re interested in the details of how that works, please see Sucuri’s post. The main thing to know is that someone would have to get you to click a link in order to take advantage. But once that is done this is a dangerous vulnerability.

Our Response

We have removed the /genericons/example.html file from public directories on our systems. This will protect all Lightning Base hosted sites from the attack, and is not a problem because the file isn’t necessary. We are also running a process to look for and delete these files periodically in case someone uploads a plugin or WP install that already has the vulnerable file.

Sites Hosted Elsewhere?

If you have sites hosted somewhere that they will not be automatically patched, I strongly encourage you to look in the JetPack and TwentyFifteen folders for the genericons/example.html file and delete it. A more complete solution would be to search your web directories for the file so you can find/delete any instances that might exist in another plugin/theme.



Author : Chris Piepho

Chris is the founder of Lightning Base. You'll find him all over around here - writing on this blog, providing customer service, and handling whatever else needs to be done. You can reach him easily by filling out our contact form and addressing your message to Chris.

Security Notice: 0-Day XSS Vulnerability – Sites at Lightning Base Are Safe
WordPress 4.2.2 Released
Click here to cancel reply.

Leave a Reply

Post Comment

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

Menu

  • Home
  • Tour
  • Pricing
  • Contact
  • About

Archives

  • November 2024
  • December 2018
  • June 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • September 2015
  • August 2015
  • July 2015
  • May 2015
  • April 2015
  • February 2015
  • December 2014
  • November 2014
  • October 2014
  • September 2014
  • August 2014
  • May 2014
  • April 2014
  • September 2013
  • June 2013
  • April 2013
  • January 2013
  • December 2012
  • November 2012
  • October 2012
  • September 2012
  • May 2012
  • March 2012
  • February 2012
  • January 2012

WP Host

Lightning Base: Making WordPress faster, easier, better. Take the tour or get started today.

From the Blog

  • Mitigating the Really Simple SSL Security Vulnerability

    Note: This blog has been pretty quiet for a long time. We're looking to change that and more frequently discuss things h...

  • WordPress 5.0

    WordPress 5.0 will be released tomorrow, December 6th. This is one of the largest updates WordPress has seen in a long t...

  • WordPress 4.5.3 Security Update Released

    WordPress 4.5.3 was released today, as announced on WordPress.org. The Update This is a security update, it is important...

  • Public Beta Invite: HTTP/2, HTTPS Caching

    We've been working on changes that enable HTTP/2 and built-in caching for HTTPS sites/pages for several months now. At t...

Menu

  • Home
  • Tour
  • Pricing
  • Contact
  • About
  • Affiliates
  • Client Login

© 2020 Lightning Base LLC. All rights reserved. | Privacy Policy | Terms of Use