Security News > 2022 > January > WordPress 5.8.3 security update fixes SQL injection, XSS flaws

WordPress 5.8.3 security update fixes SQL injection, XSS flaws
2022-01-10 15:28

The WordPress development team released version 5.8.3, a short-cycle security release that addresses four vulnerabilities, three of which are rated of high importance.

The set includes an SQL injection on WP Query, a blind SQL injection via the WP Meta Query, an XSS attack via the post slugs, and an admin object injection.

Fixes cover WordPress versions down to 3.7.37.

Fixes cover WordPress versions down to 4.1.34.

There have been no reports of the above being under active exploitation in the wild, and none of these flaws is thought to have a severe potential impact on most WordPress sites.

Php, which should be "Define('WP AUTO UPDATE CORE', true );". Automated core updates were introduced in 2013 on WordPress 3.7, and according to official stats, only 0.7% of all WP sites are currently running a version older than that.


News URL

https://www.bleepingcomputer.com/news/security/wordpress-583-security-update-fixes-sql-injection-xss-flaws/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Wordpress 7 2 95 44 18 159