TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

WordPress XSS 0day

9 点作者 jchavannes大约 10 年前

2 条评论

lol768大约 10 年前
The blogpost linked (<a href="http:&#x2F;&#x2F;klikki.fi&#x2F;adv&#x2F;wordpress2.html" rel="nofollow">http:&#x2F;&#x2F;klikki.fi&#x2F;adv&#x2F;wordpress2.html</a>) in the article is rather worrying to read - especially the &quot;Solution&quot; section which suggests Klikki Oy had a lot of trouble communicating with WordPress and getting the bug fixed.<p>Interestingly, the WordPress blog states &quot;A few hours ago, the WordPress team was made aware of a cross-site scripting vulnerability, which could enable commenters to compromise a site. The vulnerability was discovered by Jouko Pynnönen.&quot;<p>I&#x27;m not very familiar with WordPress or its plugins, but does it make use of Content-Security-Policy headers? Those might&#x27;ve helped to minimise the risk (at least for users with modern browsers) to users browsing WordPress sites.
评论 #9448917 未加载
breakingcups大约 10 年前
Let&#x27;s wait on the obligatory Cloudflare blogpost talking about how their paying customers are protected.