{"id":8064,"date":"2015-05-06T19:25:57","date_gmt":"2015-05-06T13:55:57","guid":{"rendered":"http:\/\/blog.resellerclub.com\/?p=8064"},"modified":"2017-04-04T20:44:48","modified_gmt":"2017-04-04T15:14:48","slug":"important-vulnerabilities-discovered-in-wordpress-magneto","status":"publish","type":"post","link":"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/","title":{"rendered":"IMPORTANT: Vulnerabilities Discovered in WordPress &#038; Magneto"},"content":{"rendered":"<p>At ResellerClub, we&#8217;re always looking out for the best for our resellers-\u00a0on both, the service and security front.<\/p>\n<p>Here, we&#8217;d like to draw your attention to an important development which is cause for security concerns, in two popular scripts, not resulting of anything specific to ResellerClub services &#8211; vulnerabilities in WordPress &amp; Magneto.<\/p>\n<p>Let&#8217;s take a moment to understand each vulnerability:<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>WordPress Vulnerability\u00a0<\/strong><\/span><\/p>\n<p><span style=\"text-decoration: underline;\">What is it?<\/span><\/p>\n<p>This is a new, serious vulnerability, announced recently which has the potential to cause some damage and disruption.<\/p>\n<p>Current versions of WordPress are vulnerable to a stored XSS. An unauthenticated attacker can inject JavaScript in WordPress comments. The script is triggered when the comment is viewed.<\/p>\n<p>If triggered by a logged-in administrator, under default settings the attacker can leverage the vulnerability to execute arbitrary code on the server via the plugin and theme editors.<\/p>\n<p>Alternatively the attacker could change the administrator\u2019s password, create new administrator accounts, or do whatever else the currently logged-in administrator can do on the target system. You can find more details about the impact and solution for the same <span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"http:\/\/klikki.fi\/adv\/wordpress2.html\" target=\"_blank\">here<\/a><\/span>.<\/p>\n<p><span style=\"text-decoration: underline;\">What you need to do?<\/span><\/p>\n<p>We would request you to go through the recommendations and update your WordPress website using the patch available <span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"http:\/\/klikki.fi\/adv\/wordpress2.html\" target=\"_blank\">here<\/a><\/span>.<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Magneto Vulnerability<\/strong><\/span><\/p>\n<p><span style=\"text-decoration: underline;\">What is it?<\/span><\/p>\n<p>This is a vulnerability that has been recently reported too.\u00a0The vulnerability is actually comprised of a chain of several vulnerabilities that ultimately allow an unauthenticated attacker to execute PHP code on the web server. The attacker bypasses all security mechanisms and gains control of the store and its complete database, allowing credit card theft or any other administrative access into the system.<\/p>\n<p>This attack is not limited to any particular plugin or theme. All the vulnerabilities are present in the Magento core, and affects any default installation of both Community and Enterprise Editions.\u00a0Click <span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"http:\/\/forums.myorderbox.com\/index.php?\/topic\/5513-important-vulnerabilities-discovered-in-wordpress-and-magento\/#entry11355\" target=\"_blank\">here<\/a><\/span> for more details.<\/p>\n<p><span style=\"text-decoration: underline;\">What you need to do?<\/span><\/p>\n<p>If you are using the mentioned vulnerable versions of Magento, we would request you to patch it using the updates provided in the following link :\u00a0<span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"http:\/\/blog.checkpoint.com\/2015\/04\/20\/analyzing-magento-vulnerability\/\" target=\"_blank\">http:\/\/blog.checkpoint.com\/2015\/04\/20\/analyzing-magento-vulnerability\/<\/a><\/span><\/p>\n<p>You can test your Magento website&#8217;s vulnerability using the <a href=\"https:\/\/shoplift.byte.nl\" target=\"_blank\"><span style=\"color: #0000ff;\">this tool<\/span>.<\/a><\/p>\n<p>We strongly recommend you access all your packages and patch them immediately to avoid any issues. Please feel free to contact our support helpdesk in case you have any queries.<\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground:  !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 100% !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>At ResellerClub, we&#8217;re always looking out for the best for our resellers-\u00a0on both, the service and security front. Here, we&#8217;d like to draw your attention to an important development which is cause for security concerns, in two popular scripts, not resulting of anything specific to ResellerClub services &#8211; vulnerabilities in WordPress &amp; Magneto. Let&#8217;s take<\/p>\n","protected":false},"author":40,"featured_media":8076,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[938,990,4177],"tags":[974,970,280,135,410,972],"hashtags":[],"class_list":{"0":"post-8064","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-announcements","8":"category-news-en","9":"category-wordpress","10":"tag-javascript","11":"tag-magneto","12":"tag-php","13":"tag-security","14":"tag-wordpress","15":"tag-xss"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>IMPORTANT: Vulnerabilities Discovered in WordPress &amp; Magneto<\/title>\n<meta name=\"description\" content=\"Security concerns with two new vulnerabilities in WordPress &amp; Magneto. Swift action on your part can prevent damage and disruption.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"IMPORTANT: Vulnerabilities Discovered in WordPress &amp; Magneto\" \/>\n<meta property=\"og:description\" content=\"Security concerns with two new vulnerabilities in WordPress &amp; Magneto. Swift action on your part can prevent damage and disruption.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/\" \/>\n<meta property=\"og:site_name\" content=\"ResellerClub Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/profile.php?id=100005889763273\" \/>\n<meta property=\"article:published_time\" content=\"2015-05-06T13:55:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2017-04-04T15:14:48+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Amrita\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#website\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/\",\"name\":\"ResellerClub Blog\",\"description\":\"Web Hosting &amp; Domains\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.resellerclub.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/#webpage\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/\",\"name\":\"IMPORTANT: Vulnerabilities Discovered in WordPress & Magneto\",\"isPartOf\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/#primaryimage\"},\"datePublished\":\"2015-05-06T13:55:57+00:00\",\"dateModified\":\"2017-04-04T15:14:48+00:00\",\"author\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/3022c632f8c79376e89b21ebd7e3c777\"},\"description\":\"Security concerns with two new vulnerabilities in WordPress & Magneto. Swift action on your part can prevent damage and disruption.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.resellerclub.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"IMPORTANT: Vulnerabilities Discovered in WordPress &#038; Magneto\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/3022c632f8c79376e89b21ebd7e3c777\",\"name\":\"Amrita\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/wp-content\/uploads\/2019\/08\/amrita.k-150x150.jpg\",\"contentUrl\":\"https:\/\/www.resellerclub.com\/blog\/wp-content\/uploads\/2019\/08\/amrita.k-150x150.jpg\",\"caption\":\"Amrita\"},\"description\":\"Amrita Konaiagari is the Team Lead for Content Marketing at Endurance International Group (APAC). She is also the Editor of the ResellerClub blog. She holds a Bachelor\\u2019s Degree in Psychology from St. Xavier\\u2019s College, Mumbai and a Master\\u2019s Degree in Communication & Journalism from the Mumbai University. She has 9 years of experience in Digital Marketing. She has a passion for home decor and hopes to one day be a book author.\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/author\/amrita-k\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"IMPORTANT: Vulnerabilities Discovered in WordPress & Magneto","description":"Security concerns with two new vulnerabilities in WordPress & Magneto. Swift action on your part can prevent damage and disruption.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/","og_locale":"en_US","og_type":"article","og_title":"IMPORTANT: Vulnerabilities Discovered in WordPress & Magneto","og_description":"Security concerns with two new vulnerabilities in WordPress & Magneto. Swift action on your part can prevent damage and disruption.","og_url":"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/","og_site_name":"ResellerClub Blog","article_publisher":"https:\/\/www.facebook.com\/profile.php?id=100005889763273","article_published_time":"2015-05-06T13:55:57+00:00","article_modified_time":"2017-04-04T15:14:48+00:00","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Amrita","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/www.resellerclub.com\/blog\/#website","url":"https:\/\/www.resellerclub.com\/blog\/","name":"ResellerClub Blog","description":"Web Hosting &amp; Domains","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.resellerclub.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/#primaryimage","inLanguage":"en-US","url":"","contentUrl":""},{"@type":"WebPage","@id":"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/#webpage","url":"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/","name":"IMPORTANT: Vulnerabilities Discovered in WordPress & Magneto","isPartOf":{"@id":"https:\/\/www.resellerclub.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/#primaryimage"},"datePublished":"2015-05-06T13:55:57+00:00","dateModified":"2017-04-04T15:14:48+00:00","author":{"@id":"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/3022c632f8c79376e89b21ebd7e3c777"},"description":"Security concerns with two new vulnerabilities in WordPress & Magneto. Swift action on your part can prevent damage and disruption.","breadcrumb":{"@id":"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.resellerclub.com\/blog\/important-vulnerabilities-discovered-in-wordpress-magneto\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.resellerclub.com\/blog\/"},{"@type":"ListItem","position":2,"name":"IMPORTANT: Vulnerabilities Discovered in WordPress &#038; Magneto"}]},{"@type":"Person","@id":"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/3022c632f8c79376e89b21ebd7e3c777","name":"Amrita","image":{"@type":"ImageObject","@id":"https:\/\/www.resellerclub.com\/blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/www.resellerclub.com\/blog\/wp-content\/uploads\/2019\/08\/amrita.k-150x150.jpg","contentUrl":"https:\/\/www.resellerclub.com\/blog\/wp-content\/uploads\/2019\/08\/amrita.k-150x150.jpg","caption":"Amrita"},"description":"Amrita Konaiagari is the Team Lead for Content Marketing at Endurance International Group (APAC). She is also the Editor of the ResellerClub blog. She holds a Bachelor\u2019s Degree in Psychology from St. Xavier\u2019s College, Mumbai and a Master\u2019s Degree in Communication & Journalism from the Mumbai University. She has 9 years of experience in Digital Marketing. She has a passion for home decor and hopes to one day be a book author.","url":"https:\/\/www.resellerclub.com\/blog\/author\/amrita-k\/"}]}},"_links":{"self":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/8064","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/users\/40"}],"replies":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/comments?post=8064"}],"version-history":[{"count":7,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/8064\/revisions"}],"predecessor-version":[{"id":8072,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/8064\/revisions\/8072"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/media?parent=8064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/categories?post=8064"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/tags?post=8064"},{"taxonomy":"hashtags","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/hashtags?post=8064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}