Skip to main content
  1. Home
  2. Computing
  3. News

WordPress vulnerability affects millions of sites, and yours could be next

According to a post by the security research team at Sucuri, millions of WordPress websites could be at risk for exploitation thanks to a defect in a popular theme included in the default setup.

The exploit feeds off an XSS vulnerability known as a “DOM-Based XSS,” or Document Object Model. According to the independent vetting agency, DOMs are used to teach a browser how to display headers, images, text, or links that are displayed inside a WordPress loadout theme.

Recommended Videos

The theme (called “Twenty Fifteen” despite the fact that it was released last year), is installed by default in all core builds of the current WordPress distribution, making it an especially large target for any hackers who want to catch the biggest fish they can with the smallest net.

The crack digs its claws in when a site administrator clicks a malicious link either in their email or on a phishing website while logged into WordPress, enabling an automatically scan of the server for a potential hole to get in.

What makes this especially worrisome is the fact that the bug doesn’t need your site to be running a version of Twenty Fifteen for it to be a problem. Because the theme is included in the database of every rollout, it’s automatically a given that you could be hacked.

If you own a WordPress site (regardless of the version installed), you should use the query tool to check and see if you might be vulnerable to an attack.

The larger domain hosts such as GoDaddy and ClickHost have already scrubbed through their subscriber base and removed any traces of the bug, but in case you’re either running an independent server, or your host isn’t listed here, be sure to make the change yourself to immunize you or your users from the threat.

Chris Stobing
Former Digital Trends Contributor
Self-proclaimed geek and nerd extraordinaire, Chris Stobing is a writer and blogger from the heart of Silicon Valley. Raised…
Your Firefox tabs can soon hold little notes just for you
Firefox adds tab notes so your 47 open tabs can stop judging you
Mozilla Firefox

If you are the type of person who has 50 tabs open and can’t remember why you opened half of them, Firefox might have just solved your problem.

Mozilla is quietly testing a new "Add Note" feature in the latest experimental version of the browser (Firefox Nightly). It’s super simple: you just right-click on any tab, hit "Add Note," and type a quick reminder to yourself. A little notepad icon then sits next to the tab title so you know there’s something there.

Read more
9 unexpected things I was able to do with ChatGPT (and a few you must try)
From interior design advice and , to vitamins insight and gym goals
9 unexpected things I was able to do with ChatGPT

ChatGPT has become a household name for writing emails, essays, and code – but its abilities go far beyond the obvious. 

With the latest updates, ChatGPT can now see images, browse the web, use specialized tools, and even act as an “AI agent” that carries out tasks for you. 

Read more
Drive meaningful ROI risk-free with MailChimp’s 14-day Standard Plan free trial
Transform how you connect with your audience with smart, automated marketing that drives serious results
Man sitting on chair holding a laptop, woman standing next to him

This post is brought to you in paid partnership with Mailchimp

Whether you're a creator, running a small business, or part of team looking to scale email marketing, MailChimp's Standard plan offers a combination of AI tools, automation, insights, and customization to boost growth.

Read more