Connect with us

NEWS

WordPress 5.8.1 Released to Fix Multiple Vulnerabilities via @sejournal, @martinibuster

Published

on

wordpress vulnerabilities 613a042ef3527 sej

WordPress announced a security and maintenance release, version 5.8.1. It is important to update WordPress, especially versions 5.4 to 5.8 in order fix three security issues.

WordPress 5.8.1 Security and Maintenance Release

It’s not uncommon for WordPress or any software for that matter to publish a bug fix update following a major version update in order to fix unforeseen issues as well as introduce improvements that didn’t make it in time for the major release.

In WordPress those updates are called a maintenance release.

This update also includes a security update, which is somewhat uncommon for the WordPress core. That makes this update more important than the typical maintenance release.

Advertisement

Continue Reading Below

WordPress Security Issues Fixed

WordPress 5.8.1 fixes three vulnerabilities:

Advertisement
  1. A data exposure vulnerability within the REST API
  2. Cross-Site Scripting (XSS) vulnerability in the Gutenberg block editor
  3. Multiple critical to high severity vulnerabilities in the Lodash JavaScript Library

All three of the above vulnerabilities are so concerning that the WordPress announcement recommends immediately updating WordPress installations.

REST API Vulnerability

The WordPress REST API is an interface that allows plugins and themes to interact with the WordPress core.

The REST API has been a source of security vulnerabilities, including most recently with the Gutenberg Template Library & Redux Framework vulnerability that affected over a million websites.

Advertisement

Continue Reading Below

This vulnerability is described as a data exposure vulnerability, which means that sensitive information could be revealed. There are no other details at this time regarding what kind of information but it could be as severe as passwords to data that could be used to mount an attack through another vulnerability.

WordPress Gutenberg XSS Vulnerability

Cross-Site Scripting (XSS) vulnerabilities happen relatively frequently. They can happen whenever there is a user input like a contact or email form, any kind of input that is not “sanitized” to prevent the upload of scripts that can trigger unwanted behavior in the WordPress installation.

Advertisement

The Open Web Application Security Project (OWASP) describes the potential harm of XSS vulnerabilities:

“An attacker can use XSS to send a malicious script to an unsuspecting user. The end user’s browser has no way to know that the script should not be trusted, and will execute the script.

Because it thinks the script came from a trusted source, the malicious script can access any cookies, session tokens, or other sensitive information retained by the browser and used with that site. These scripts can even rewrite the content of the HTML page.”

This specific vulnerability affects the Gutenberg block editor.

Advertisement

Continue Reading Below

WordPress Lodash JavaScript Library Vulnerabilities

These vulnerabilities may be the most concerning. The Lodash JavaScript library is a set of scripts used by developers that have been found to have multiple vulnerabilities.

Advertisement

The latest and safest version is Lodash 4.17.21.

The U.S. Homeland Security sponsored CVE List website details the vulnerability:

“Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.”

There appear to be many other vulnerabilities affecting the Lodash library in the 4.1.7 branch as well.

WordPress Urges Immediate Updating

These security vulnerabilities add a sense of urgency to this update. All publishers are recommended by WordPress to update.

Advertisement

Continue Reading Below

Advertisement

The official WordPress announcement recommends updating:

“Because this is a security release, it is recommended that you update your sites immediately. All versions since WordPress 5.4 have also been updated.”

Citations

WordPress 5.8.1 Security and Maintenance Release

CVE Lodash Vulnerability Description CVE-2021-23337

Searchenginejournal.com

Keep an eye on what we are doing
Be the first to get latest updates and exclusive content straight to your email inbox.
We promise not to spam you. You can unsubscribe at any time.
Invalid email address