Skip to main content

WordPress vulnerability affects millions of sites, and yours could be next

wordpress vulnerability affects millions of sites and yours could be next n6yxinh
Image Credit: WordPress
According to a post by the security research team at Sucuri, millions of WordPress websites could be at risk for exploitation thanks to a defect in a popular theme included in the default setup.

The exploit feeds off an XSS vulnerability known as a “DOM-Based XSS,” or Document Object Model. According to the independent vetting agency, DOMs are used to teach a browser how to display headers, images, text, or links that are displayed inside a WordPress loadout theme.

The theme (called “Twenty Fifteen” despite the fact that it was released last year), is installed by default in all core builds of the current WordPress distribution, making it an especially large target for any hackers who want to catch the biggest fish they can with the smallest net.

The crack digs its claws in when a site administrator clicks a malicious link either in their email or on a phishing website while logged into WordPress, enabling an automatically scan of the server for a potential hole to get in.

What makes this especially worrisome is the fact that the bug doesn’t need your site to be running a version of Twenty Fifteen for it to be a problem. Because the theme is included in the database of every rollout, it’s automatically a given that you could be hacked.

If you own a WordPress site (regardless of the version installed), you should use the query tool to check and see if you might be vulnerable to an attack.

The larger domain hosts such as GoDaddy and ClickHost have already scrubbed through their subscriber base and removed any traces of the bug, but in case you’re either running an independent server, or your host isn’t listed here, be sure to make the change yourself to immunize you or your users from the threat.

Editors' Recommendations

Chris Stobing
Former Digital Trends Contributor
Self-proclaimed geek and nerd extraordinaire, Chris Stobing is a writer and blogger from the heart of Silicon Valley. Raised…
The RTX 4090 is more popular on Steam than any AMD GPU
Nvidia GeForce RTX 4090 GPU.

Despite being easily the fastest graphics card you can buy right now, the RTX 4090 is a niche product. At $1,600, it's out of the conversation for the vast majority of gamers. Still, that hasn't stopped the GPU from reaching a high ranking in Steam's hardware survey. According to the latest survey, the RTX 4090 is in 0.96% of gaming PCs running Steam -- more than any individual AMD GPU.

Although it's no surprise that Nvidia tops the charts in the Steam hardware survey -- the most recent report says Nvidia is represented in 76.59% of PCs compared to AMD's 15.79% -- it's shocking to see such an expensive GPU rank so highly. Compared to last month, the RTX 4090 even gained 0.11%, despite only being available above list price.

Read more
11 best graphics cards of 2024: the GPUs I’d recommend to any PC gamer
RTX 3080 graphics cards among other GPUs.

Now that Nvidia and AMD have released the last GPUs we're likely to see this generation, it's time to look back and see what made the cut among the best graphics cards. Although there are definitely weak options on the market, some smart price shifting and well-timed refreshes for 2024 have given current-gen graphics cards new life.

We've reviewed every graphics card released by Nvidia, AMD, and Intel over the past few years, testing them in a variety of games to see how they hold up. If you're new to graphics cards and PC gaming in general, make sure to check out our guide on how to install a graphics card and on the best GPU deals currently available.

Read more
4 CPUs you should buy instead of the Intel Core i9-13900K
Intel Core i9-13900K held between fingertips.

Intel's Core i9-13900K is one of the best processors you can buy. The 24-core behemoth can rip through productivity workloads with ease, and it's easily one of the fastest gaming CPUs money can buy. Even with so much power under the hood, it's not the right choice for everyone.

Supreme power comes at a supreme cost, and for the Core i9-13900K, that comes in the form of heat and power draw. In addition, a recent wave of instability has hit Intel's high-end CPUs like the Core i9-13900K, making alternatives a bit more attractive.

Read more