Major Vulnerability Hits WordPress

LOS ANGELES — A vital security warning has been issued to the many users of self-hosted WordPress installations — a user base that includes countless adult websites.

In addition to affecting WordPress users, the exploit, which employs an XML Quadratic Blowup Attack, also affects users of the Drupal platform, which while relatively popular, does not have the vast market share of the Open Source WordPress solution — which may be adult entertainment’s most widely used content management system (CMS) and publishing platform.

As an example of the platform’s overall reach, recent World Wide Web Consortium (WC3) statistics reveal that 23 percent of today’s web is powered by WordPress.

The exploit is capable of immediately crashing a website, by causing complete usage of available CPU power and memory, while also causing a Denial of Service attack on the software’s MySQL database — but fortunately, this attack can be defeated by simply updating the software to its latest version.

The WordPress security team has now released the WordPress 3.9.2 system update and is strongly encouraging users to update their sites immediately. The Drupal security team has likewise issued a fix and also recommends users immediately update to its latest version.

The exploit was discovered by Salesforce.com security expert Nir Goldshlager, who explains that this attack inflates a small XML document of several hundred kilobytes into multiple gigabytes, crushing any Apache server in a matter of moments.

“If an attacker defines the entity ‘&x;’ as 55,000 characters long, and refers to that entity 55,000 times inside the ‘DoS’ element, the parser ends up with an XML Quadratic Blowup attack payload slightly over 200 KB in size that expands to 2.5 GB when parsed,” Goldshlager says. “This expansion is enough to take down the parsing process.”

Goldshlager has released a video demonstrating the attack in action.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

MrPornGeek Launches 'Visibility Boost' System

MrPornGeek has launched a new visibility boost system.

New Federal Bills Aim to Repeal Section 230

Members of Congress this week introduced two bills calling for the repeal of Section 230 of the Communications Decency Act, which protects interactive computer services — including adult platforms — from liability for user-generated content.

RM11 Joins Pineapple Support as Supporter-Level Sponsor

RM11 has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

Mark Spiegler Named XBIZ Talk Guest for 2026 LA Conference

XBIZ is pleased to announce that famed talent agent Mark Spiegler, impresario of the Spiegler Girls agency, will join an exclusive talk session at XBIZ 2026, the latest edition of North America’s largest adult industry conference, set to take place Jan. 12-15 at the Kimpton Everly Hotel in Hollywood.

Gataca Introduces Passkey Integration

Spain-based age verification provider Gataca has debuted its new passkey integration.

GloryPay Announces New Financial App

European fintech company GloryPay has announced the launch of its financial app for industry members.

Creator of Hentaied, Parasited Launches New Site 'MonsterPorn'

Romero Mr. Alien, the creator of Parasited and Hentaied, has launched new paysite MonsterPorn.com.

House of Lords Approves UK Plan to Outlaw 'Choking' Content

The House of Lords, the U.K.’s upper house of Parliament, has agreed to amendments to the pending Crime and Policing Bill that would make depicting “choking” in pornography illegal and designate it a “priority offense” under the Online Safety Act.

Indiana Sues Aylo Over AV, Calls IP Address Blocking 'Insufficient'

Indiana Attorney General Todd Rokita has filed a lawsuit against Aylo, alleging that the company and its affiliates have violated both Indiana’s age verification law and the state’s Deceptive Consumer Sales Act.

House Committee Amends, Advances Federal AV Bill

A U.S. House of Representatives subcommittee voted Thursday to amend the SCREEN Act, which would make site-based age verification of users seeking to access adult content federal law, and to advance the bill for review by the full Committee on Energy and Commerce.

Show More