Major Vulnerability Hits WordPress

LOS ANGELES — A vital security warning has been issued to the many users of self-hosted WordPress installations — a user base that includes countless adult websites.

In addition to affecting WordPress users, the exploit, which employs an XML Quadratic Blowup Attack, also affects users of the Drupal platform, which while relatively popular, does not have the vast market share of the Open Source WordPress solution — which may be adult entertainment’s most widely used content management system (CMS) and publishing platform.

As an example of the platform’s overall reach, recent World Wide Web Consortium (WC3) statistics reveal that 23 percent of today’s web is powered by WordPress.

The exploit is capable of immediately crashing a website, by causing complete usage of available CPU power and memory, while also causing a Denial of Service attack on the software’s MySQL database — but fortunately, this attack can be defeated by simply updating the software to its latest version.

The WordPress security team has now released the WordPress 3.9.2 system update and is strongly encouraging users to update their sites immediately. The Drupal security team has likewise issued a fix and also recommends users immediately update to its latest version.

The exploit was discovered by Salesforce.com security expert Nir Goldshlager, who explains that this attack inflates a small XML document of several hundred kilobytes into multiple gigabytes, crushing any Apache server in a matter of moments.

“If an attacker defines the entity ‘&x;’ as 55,000 characters long, and refers to that entity 55,000 times inside the ‘DoS’ element, the parser ends up with an XML Quadratic Blowup attack payload slightly over 200 KB in size that expands to 2.5 GB when parsed,” Goldshlager says. “This expansion is enough to take down the parsing process.”

Goldshlager has released a video demonstrating the attack in action.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

New Creator Directory 'TrustyFans' Launches

TrustyFans, a new directory for creators, has officially launched.

Corey Silverstein to Host Webinar on 'SCOTUS Age Verification Ruling'

Where Does Age Verification Go From Here," to livestream July 10 at 4 p.m. (EDT).

FSC Publishes Guidance on Google Analytics Lawsuits

The Free Speech Coalition (FSC) has published guidance on how adult websites can protect themselves in the wake of several consumer class action lawsuits filed against sites for using Google Analytics.

BranditScan, CreatorTraffic Partner for 'Creators & Agencies' Initiative

BranditScan and advertising network CreatorTraffic have partnered for an initiative to help creators and agencies generate traffic and protect their content.

Teasy Agency Joins Pineapple Support as Supporter-Level Sponsor

Teasy Agency has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

Aylo, Pineapple Support Partner for Mental Health Video Series

Aylo has teamed up with Pineapple Support to create a safety video series aimed at educating performers and creators about mental health.

Ofcom Investigates FTV Sites for Possible AV Noncompliance

U.K. media regulator Ofcom is investigating First Time Videos, which operates the sites FTVGirls.com and FTVMilfs.com, for possible failure to comply with age assurance requirements under the Online Safety Act.

Stalwart Defender: Jeffrey Douglas on 30 Years Fighting for Free Expression

“If you had told me in 1995 that I would be on the FSC board for 30 years, I would have laughed out loud,” says Jeffrey Douglas.

FSC Publishes Analysis of Federal Trade Commission Event Promoting AV

Free Speech Coalition (FSC) has published an analysis of a Federal Trade Commission (FTC) event held this week that promoted age verification among other forms of speech regulation.

GirlsDoPorn Owner Michael Pratt Pleads Guilty to Sex Trafficking

Michael Pratt, former owner of the rogue website GirlsDoPorn, pleaded guilty in the U.S. District Court for the Southern District of California on Thursday to sex trafficking and conspiracy to commit sex trafficking charges, according to a report by City News Service.

Show More