Skip to main content
Ahosting Logo
  • Hosting
    • WordPress Hosting
      Fast, secure hosting for WordPress sites
    • Web Hosting
      Reliable, affordable hosting for sites
    • FFMpeg Hosting
      Fast hosting for FFmpeg projects
    • Reseller Hosting
      Start hosting biz with white-label plans
    • VPS Hosting
      Scalable VPS with full control & power
    • Dedicated Server
      High-power servers for max security
    • WooCommerce Hosting
      Fast hosting for WooCommerce shops
  • Domain
    • Register a Domain
      Secure your domain name in minutes
    • Domain Transfer
      Move domains to Ahosting with ease
    • Premium SSL Certificate
      Enterprise SSL to build customer trust
  • Support
    • Submit A Ticket
      Expert 24/7 help from our support team
    • Abuse Report
      Report abuse to keep network safe
    • Knowledge Base
      Quick answers via step-by-step guides
  • Company
    • Blog
      Expert articles to power your online growth
    • Compare Hosts
      Side-by-side comparison
    • Datacenter
      Secure, high tech datacenter for hosting
    • About Us
      Learn about our mission, values & team
    • Contact Us
      Contact sales for plans, pricing & advice
    • Sitemap
      Find info fast with our clear site map
My Account
Ahosting Logo
  • Hosting
    • Web Hosting
    • WordPress Hosting
    • FFMpeg Hosting
    • Reseller Hosting
    • VPS Hosting
    • Dedicated Server
    • WooCommerce Hosting
  • Domain
    • Register a Domain
    • Domain Transfer
    • Premium SSL Certificate
  • Support
    • Knowledge Base
    • Abuse Report
    • Submit A Ticket
  • Company
    • About Us
    • Contact Us
    • Blog
    • Sitemap
    • Datacenter
  • Legal
    • Privacy Policy
    • Terms of Service
    • Acceptable Use Policy
    • Service Legal Agreement
    • Resource Abuse Policy
My Account

AHosting Blog Home

Keeping Your Website Safe From WordPress’s XSS Vulnerability

XSS Vulnerability

Matt Chrust

Director of Business Development, AHosting Matt has led business development at AHosting since the company’s founding in 2002. He writes about WordPress hosting infrastructure, server performance, and the evolving requirements of WordPress sites at scale.

Last Updated

December 2, 2014
Home » Security » Keeping Your Website Safe From WordPress’s XSS Vulnerability

Last month, a Finnish IT company by the name of Klikki Oy identified a critical vulnerability in WordPress – one which has been present in the platform for approximately four years. It allows attackers to enter comments which include malicious JavaScript. Once the script in these comments is executed, the attacker could then do anything from infecting the PCs of visitors to completely hijacking the website; locking the original administrator out of their account.

“Program code injected in comments would be inadvertently executed in the blog administrator’s web browser when they view the comment,” explained security expert Jouko Pynonnen. “The rogue code could then perform administrative operations by covertly taking over the administrator account. Such operations include creating a new administrator account, changing the current administrator password and, in the most serious case, executing attacker-supplied PHP code on the server. This grants the attacker operating-system-level access on the hosting server.”

Yeah, it’s pretty bad.

Believe it or not, it actually gets a whole lot worse. According to Ars Technica, the exploit could, based on current usage statistics, affect upwards of 86% of WordPress-powered websites. The good news is that WordPress has already issued an update which patches out this vulnerability along with several other, unrelated bugs. It’s also worth mentioning that WordPress 4.0, released in September, is also invulnerable to the attack.

Version 4.0 can be downloaded here; 4.01 here – I’d advise installing one of them as soon as humanly possible.

Of course, for many websites, that might not be an option. Upgrading immediately might mean sacrificing functionality on a number of critical plugins, many of which might not be compatible with the new version. So…assuming you can’t immediately apply the patch to your WordPress server, how can you make sure you’re still protected?

There are a few methods.

First and foremost, Klikki reports that Akismet’s comment plugin is able to filter any comments attempting to make use of the exploit. For websites that don’t use Akismet, Klikki has released a plugin of its own; one which neuters the exploit by disabling texturization (something you could also do manually, with a PHP workaround). Finally – and this may not be an ideal solution either – you might consider disabling comments altogether until you can patch your site.

After all, attackers can’t exploit a feature that doesn’t exist, right?

By far, this is the biggest security vulnerability that’s been revealed in WordPress in years. The ability to lock an administrator out of their website with a few pieces of code isn’t something to be taken lightly. As such, this isn’t something you can afford to ignore – if you want to keep your website safe, secure, and completely under your control, you need to take action.

Trust me – you’ll sorely regret it if you don’t.

Image: Flickr/Marina Shemesh

Related posts:

More WordPress Plugin VulnerabilitiesMore WordPress Plugin Vulnerabilities Have Surfaced – Here’s What You Need To Know CMS Targeted AttacksCMS-Targeted Attacks Are Only Going To Get More Frequent: Here’s How To Protect Yourself concrete5Why Concrete5 Is The Best Choice For A User Driven Website Default ThumbnailTake Control of Video Comments
«Five WordPress Plugins Your Blog Needs To Have
How WordPress Can Supercharge Your Lead Generation Efforts»

Categories

  • CMS
  • Concrete5
  • Drupal
  • FFmpeg / Video Hosting
  • Hosting Guides
  • How To
  • Joomla
  • MODX
  • News Releases
  • Security
  • SEO
  • Uncategorized
  • Video Content
  • Web Hosting News
  • WooCommerce
  • WordPress

Lets Connect!

  • X
  • Facebook
  • LinkedIn
  • Instagram
  • YouTube
  • Pinterest
Ahosting Logo

Hosting

  • WordPress Hosting
  • Web Hosting
  • FFMpeg Hosting
  • WooCommerce Hosting
  • Reseller Hosting
  • VPS Hosting
  • Dedicated Server

Domain

  • Register a Domain
  • Domain Transfer
  • Premium SSL Certificate

Support

  • Knowledge Base
  • Abuse Report
  • Submit A Ticket

Company

  • About Us
  • Datacenter
  • Contact Us
  • Blog
  • Sitemap

Legal

  • Privacy Policy
  • Terms of Service
  • Acceptable Use Policy
  • Service Legal Agreement
  • Resource Abuse Policy
  • Hosting +
    • WordPress Hosting
    • Web Hosting
    • FFMpeg Hosting
    • Woocommerce Hosting
    • Reseller Hosting
    • VPS Hosting
    • Dedicated Server
  • Domain +
    • Register a Domain
    • Domain Transfer
    • Premium SSL Certificate
  • Support +
    • Knowledge Base
    • Abuse Report
    • Submit A Ticket
  • Company +
    • About Us
    • Datacenter
    • Contact Us
    • Blog
    • Sitemap
  • Legal +
    • Privacy Policy
    • Terms of Service
    • Acceptable Use Policy
    • Service Legal Agreement
    • Resource Abuse Policy

Copyright © All Rights Reserved