WordPress 3.1.4 Gets Clickjacking Protection | Internet News

WordPress 3.1.4 Gets Clickjacking Protection

May 27, 2011
1 minute read

The open source WordPress blogging application is being updated to version 3.1.3 this week adding multiple security fixes and improvements.

Perhaps the biggest security improvement is the inclusion of clickjacking protection support in WordPress. Clickjacking was first discussed as an attack vector back in 2008 by Whitehat Security researcher Jeremiah Grossman. In a clickjack attack, an element from a third party website is hidden behind or above an item on the website a reader is viewing. When the reader clicks on an item they believe to be legitimate, they are in fact also clicking on the secondary item as well.

Browsers began implementing specifications to protect against clickjacking in 2009. The key technique is named X-FRAME-OPTIONS and provides a mechanism by which website owners can prevent a page from rendering inside of a frame on another site.

WordPress 3.1.3 release now supports X-FRAME-OPTIONS for the admin and login pages of a WordPress site.


Read the full story at eSecurityPlanet:


WordPress Gets Clickjacking Protection

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.