WordPress announced it was publishing maintenance and security release that patches multiple vulnerabilities including one that could lead to full site takeover.. in WordPress core that allows arbitrary shortcode execution. Cross-site scripting in the post link navigation block. Reflected cross-site scripting in the application passwords screen. Cross-site scripting in the footnotes block. Some of the vulnerabilities are due to sanitization, which means that data that is submitted is not filtering out malicious inputs.. WordPress developer page for sanitization informs.. Sanitizing input is the process of securing cleaning filtering input data.. advisory about the security release posted by Wordfence notes that at least one of the vulnerabilities contained the potential for full site takeover.. WordPress advises all users to verify that their WordPress installations are updated to the version, WordPress version 6.3.2..
Read more