WordPress Releases Critical Security Update

LOS ANGELES — Less than a week after the release of WordPress Version 4.2, a critical security update was released today — along with an admonition for all users to immediately update their installations.

Debuting on April 23, with a goal of improving WordPress’ communication, sharing and simplicity, Version 4.2, nicknamed “Powell” in honor of jazz pianist Bud Powell, offers easier ways to share content, while providing extended character support, enhanced embed options, and streamlined plugin updates.

Now, an emergency patch, Version 4.2.1, has been released to the public and is an update for all previous WordPress versions. The patch addresses a cross-site scripting vulnerability that could enable comment posters to compromise a site.

As for who is affected by this vulnerability, all WordPress-powered sites are at risk if they allow users to post comments via the integrated commenting system.

“An attacker could leverage a bug in the way comments are stored in the site’s database to insert malicious scripts on your site, thus potentially allowing them to infect your visitors with malware, inject SEO spam or even insert backdoor in the site’s code if the code runs when in a logged-in administrator browser,” Marc-Alexandre Montpas wrote for Sucuri.net, advising WordPress site admins to “definitely disable comments on your site until a patch is [installed] to protect your site and customers.”

The unexpected update fuels critics that claim the Open Source WordPress core lacks security, but the opposite is true: As the world’s most popular publishing platform, WordPress is actively embraced by tens of thousands of developers and used in countless websites, making its underlying code perhaps the most scrutinized software on the planet. This means that vulnerabilities are revealed and mitigated far more often than those contained in proprietary systems that are only well-known to a relative handful of developers and users.

WordPress 4.2.1 is now rolling out as an automatic update for sites that support them.

To manually update an installation, download WordPress 4.2.1 or click “Update Now” from the admin Dashboard. 

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Creator of Hentaied, Parasited Launches New Site 'Vampired'

Romero Mr. Alien, the creator of Parasited and Hentaied, has launched Vampired.com as both a stand-alone paysite and part of the Hentaied.Pro streaming platform.

Australian eSafety Commissioner Demands Stricter Child Protection Codes

Australia’s online safety regulator, eSafety, is once again reviewing a “final” draft of industry codes to protect children from pornography and other age-inappropriate content, after eSafety Commissioner Julie Inman Grant rejected the previously announced “final” codes as insufficiently stringent.

Nerdgasm: A Look at the Naughty Side of Pop Culture Geekdom

From “Call of Duty” to cosplay, from tabletop dice rolls to dungeon-inspired dirty talk, the worlds of geek fandom and fantasy are no longer confined to the basement. They’ve kicked down the door, shed the “Firefly” tee and gone full frontal.

Kyrgyzstan Parliament Moves to Outlaw Internet Pornography

A parliamentary committee of the Supreme Council of Kyrgyzstan on Tuesday approved a measure to outlaw online adult content in the country.

Sweden Bans Purchase of 'Remote' Sexual Services

The Riksdag, Sweden’s parliament, has approved a proposal to criminalize purchasing sexual services performed remotely by streamers and custom content creators.

Asa Akira to Deliver XBIZ Talk at Miami Conference

XBIZ is pleased to announce that decorated performer, Pornhub brand ambassador, and author Asa Akira is set to deliver an exclusive talk at XBIZ Miami.

JustFor.fans Launches 'Fentanyl Test Strip' Initiative

JustFor.fans (JFF) has launched a test strip initiative to combat the nationwide fentanyl crisis.

2025 XBIZ Miami Speaker Lineup Announced

XBIZ is pleased to announce the release of the full speaker lineup for XBIZ Miami, the latest edition of the adult industry’s premier summer conference, set to take place May 19-22 at the Nautilus Sonesta Miami Beach hotel in South Beach.

AV Bulletin: Arizona's About-Face, What New Laws Mean for Adult

Industry stakeholders and free speech advocates have anxiously been awaiting the Supreme Court’s decision in Free Speech Coalition v. Paxton, which could significantly impact state age verification laws around the United States. In the meantime, state legislatures continue to weigh and pass AV bills, the U.K. and the EU are moving ahead with their own AV mandates and strategies, and legal challenges continue to play out in U.S. courts — with some cases on hold pending the SCOTUS ruling in Paxton.

Million Billion Media Launches New Website

Management and PR agency Million Billion Media (MBM) has launched a new website.

Show More