WordPress Update
2634Warning Date
Severity Level
Warning Number
Target Sector
1 November, 2020
● High
2020-1993
All
Description:
WordPress has released security update to address multiple vulnerabilities in the following versions:
- XCloner Backup and Restore
- 4.2.1 – 4.2.12
Threats:
Attacker could exploit this vulnerability by doing the following:
- Privilege escalation
- Cross-site request forgery (CSRF)
- Cross-Site Scripting (XSS) attack
- Remote code execution
Best practice and Recommendations:
The CERT team encourages users to review WordPress security advisory and apply the necessary updates: