WordPress Upgrade to 3.3.2: Fixes 11 Vulnerabilities

WordPress has released version 3.3.2 and now available to upgrade all wordpress installs. WordPress 3.3.2 is a security update for all previous versions.

Three external libraries included in WordPress received security updates:

Plupload (version 1.5.4), which WordPress uses for uploading media.
SWFUpload, which WordPress previously used for uploading media, and may still be in use by plugins.
SWFObject, which WordPress previously used to embed Flash content, and may still be in use by plugins and themes.

The above vulnerabilities were discolosed by Neal Poole, Nathan Partlan and Szymon Gruszecki. WordPress 3.3.2 also addresses:

  • Limited privilege escalation where a site administrator could deactivate network-wide plugins when running a WordPress network under particular circumstances, disclosed by Jon Cave of our WordPress core security team, and Adam Backstrom.
  • Cross-site scripting vulnerability when making URLs clickable, by Jon Cave.
  • Cross-site scripting vulnerabilities in redirects after posting comments in older browsers, and when filtering URLs. Thanks to Mauro Gentile for responsibly disclosing these issues to the security team.

These issues were fixed by the WordPress core security team. Five other bugs were also fixed in version 3.3.2. Consult the change log for more details.

Download WordPress 3.3.2 or update now from the Dashboard → Updates menu in your site’s admin area.

About the Author

I'm Shubham Yadav, B.Tech(I.T) Graduate from Behror, Rajasthan. You can follow me on Twitter. You also subscribe to Hack Illusion Feed via RSS or Email.

Leave A Response

CommentLuv badge