Skip to main content

WordPress fixes huge security vulnerability, all users instructed to update

wordpress vulnerability version 472 plug in
INBJ / 123RF
A serious zero-day vulnerability has been discovered in WordPress, and fixed as of its most recent stable release. All WordPress users are encouraged to make sure that they have updated their installation to version 4.7.2, as otherwise their site could be hijacked.

It’s thought that the exploit could give attackers the ability to modify the content on any post or page that’s part of a site built with WordPress, as per a report from Tripwire. Obviously, this lends itself to garden variety vandalism, but there’s also the threat of a much more troubling form of attack.

The vulnerability could be used to introduce harmful links into otherwise benign content. These links could take users to sites that install malicious software on their computers, or even be utilized as one element of a larger phishing scam, using the WordPress site as cover.

The problem was discovered by researchers at security firm Sucuri, which notified WordPress on January 20. The vulnerability was kept quiet at the time, because a fix had to be developed, and making the issue public could potentially have allowed malicious entities to take advantage.

Major WordPress hosting services and security companies were notified about the vulnerability ahead of its existence being disclosed to the public. Data from these organizations showed no indication that attackers had been able to exploit the issue.

However, now that the problem has been made public, it’s possible that criminal entities could use the vulnerability to target WordPress installations that aren’t up to date. Version 4.7.2 has been available since January 26, but users that don’t have automatic updates activated will need to initiate the process manually.

That means that if you have a WordPress site set up that you haven’t looked at in a while, it’s time to make sure it’s running version 4.7.2. It only takes a moment to check that you’re up to date — but if hackers manage to exploit this vulnerability on your site, you’re in for a much bigger headache.

Editors' Recommendations

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
This HP laptop is discounted from $519 to $279
HP 14 laptop with intel Celeron on desk.

There are laptop deals for top-of-the-line machines, but if you only need a basic device for your day-to-day needs, don't spend more than you should by taking advantage of Walmart's offer for the HP 14-inch Laptop. Instead of $519, you'll only have to pay $279 for savings of $240. That's an extremely affordable price for a brand new laptop, but we don't think it will last long. To make sure that you don't miss out on the discount, it's highly recommended that you proceed with the transaction as soon as possible.

Why you should buy the HP 14-inch Laptop
The HP 14-inch Laptop will never be able to match up to the speed of the best laptops, which is expected because of its price. However, if you're thinking about using the device for simple tasks like browsing the internet, watching streaming shows, and typing documents, then its 13th-generation Intel Core i3-N305 processor, integrated Intel UHD Graphics, and 8GB of RAM will be enough. The laptop also ships with Windows 11 Home pre-installed in its 256GB SSD, for an operating system that will be familiar for most people.

Read more
How to connect a keyboard and mouse to the Steam Deck
Steam Deck with Keyboard.

One of the best features of the Steam Deck is its varied controls, from face buttons, to joysticks, to touch controls. But there's never a substitute for a full size keyboard and mouse, and fortunately, you can connect them straight to the Steam Deck. It supports wired and wireless connections, although you'll need a USB hub if you want to use a USB connection.

Read more
This ultra-portable Lenovo 2-in-1 laptop is discounted from $649 to $199
lenovo 500w 2 in 1 laptop deal april 2024 classroom

For super cheap laptop deals, take a look at Lenovo right now. You can pay just $199 and get a Lenovo 500w 2-in-1 laptop. According to Lenovo’s estimated value system, the laptop normally costs $649 which is potentially a little overly optimistic but what we do know is that $199 for a 2-in-1 laptop is incredibly cheap. If you simply want an inexpensive laptop for basic typing of documents or web browsing, you’ll be happy with the Lenovo 500w 2-in-1 laptop. Here’s all we know about it.

Why you should buy the Lenovo 500w 2-in-1 Laptop
The Lenovo 500w 2-in-1 laptop keeps things simple with its hardware but you know you’re in safe hands as Lenovo is one of the best laptop brands. Here, you get an Intel Pentium Silver N6000 processor along with 8GB of memory and 128GB of SSD M.2 storage. At this price, we’re delighted to see 8GB of memory rather than 4GB and also the use of an SSD instead of eMMC. Such additions means the Lenovo 500w 2-in-1 laptop will be a little speedier than other laptops in this price range.

Read more