SHARE
Facebook X Pinterest WhatsApp

Open Source WordPress 3.5.2 Updated for Server-Side Request Forgery Attacks

Jun 21, 2013

wordpressFrom the ‘Why are you reading this? Update NOW’ files:

In recent years, the open source WordPress content management (nee Blog) platform has emerged to become the dominant player in web CMS space. That’s why when there is a security update you should RUN DON’T WALK to patch.

WordPress 3.5.2 is out today fixing 12 flaws of varying severity.

Top of the list (and top of mind for me) is: “Blocking server-side request forgery attacks, which could potentially enable an attacker to gain access to a site.”

and

Multiple fixes for cross-site scripting.

Cross-Site Scripting (XSS) attacks have long been among the top attack vectors so it’s great to see swift action from WordPress in fixing these flaws.

If you’re already running a WordPress 3.5.x site, you can update your site easily from the dashboard – which is something you should do – NOW.

Sean Michael Kerner is a senior editor at InternetNews.com. Follow him on Twitter @TechJournalist.

Recommended for you...

Insteon’s Surprise Failure Highlights the Problems with Smart Home Tech
Rob Enderle
Apr 22, 2022
Does Meta Have a Death Wish?
Rob Enderle
Apr 14, 2022
U.S. Needs to Protect Tech Leadership: Qualcomm
Rob Enderle
Apr 8, 2022
Best Internet Security Software
Devin Partida
Mar 23, 2022
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.