IT之家 AI

WordPress 7.1.3 Released: Fixes 7 Vulnerabilities, 3 of Which Were Reported by Anthropic

ITHome reported on October 7 that WordPress released version 7.1.3 yesterday (October 6), fixing 7 security vulnerabilities in the platform core and resolving 4 program bugs. Of the 7 security vulnerabilities fixed this…

ITHome Report on October 7: WordPress released version 7.1.3 yesterday (October 6),fixing 7 security vulnerabilities in the platform core and resolving 4 program bugs.

Of the 7 security vulnerabilities fixed this time, AI company Anthropic reported 3, Trail of Bits and Patchstack each reported 1, another 1 was submitted by three independent researchers, and the last 1 was discovered by the WordPress security team itself.

According to the blog post cited by ITHome, the most easily exploited vulnerability is located in the comment management interface and is a stored cross-site scripting (XSS) issue, reported by Thomas Chauchefoin of Trail of Bits. The malicious script lurks in the pending comments queue and can be triggered when an administrator opens the page.

Among the 3 vulnerabilities reported by Anthropic, one exists in the WXR exporter, where attacker input is first stored and only poses a threat when a user performs a content export and the system reuses that input to build a database query.

In addition, there is a denial-of-service vulnerability in the WP_Http::make_absolute_url () method, as well as a privilege issue allowing users with the author role to improperly mark posts as sticky.

Original source

IT之家 AI

Content notes

Original publication and rights belong to the source.

Machine translation · Refer to the original