Wordpress Cross Site Scripting Vulnerability Fixed by 4.2.1


Description   A vulnerability has been identified in Wordpress.
A remote attacker could exploit it in order to execute arbitrary Javascript or HTML code by inciting their victim into following a specially crafted link.
This vulnerability stems from a improper filtering of users input in comment fields.
To trigger this vulnerability, the attacker must put a text exceeding 64kb in size (MySQL TEXT type limit size) in the comment field.
A proof of concept is available.
Updated, 04/05/2015:
The wordpress packages provided by Debian Squeeze 6 are vulnerable.
Updated, 07/05/2015:
The de-wordpress, ja-wordpress, ru-wordpress, wordpress, zh-wordpress-zh_CH and zh-wordpress-zh_TW packages provided by FreeBSD are vulnerable.
     
Vulnerable Products   Vulnerable OS:
Fedora (Red Hat) - 20, 21FreeBSD (FreeBSD)GNU/Linux (Debian) - 6, 7, 8Vulnerable Software:
WordPress (WordPress) - 4.1.1, 4.1.2, 4.2
     
Solution   Fixed wordpress packages for Debian Squeeze 6 are available in LTS section.
     
CVE   CVE-2015-3440
     
References   - Klikki: WordPress 4.2 Stored XSS
http://klikki.fi/adv/wordpress2.html
- Wordpress: WordPress 4.2.1 Security Release
https://wordpress.org/news/2015/04/wordpress-4-2-1/
oss-sec: WordPress 4.2 stored XSS
http://seclists.org/bugtraq/2015/Apr/179
oss-sec: WordPress 4.2.1 security update
CVE please
http://seclists.org/oss-sec/2015/q2/292
- DebianSecurityTracker : wordpress
https://security-tracker.debian.org/tracker/CVE-2015-3440
DSA 3250-1 : wordpress security update
http://lists.debian.org/debian-security-announce/debian-security-announce-2015/msg00138.html
VuXML : wordpress -- cross-site scripting vulnerability
http://www.vuxml.org/freebsd/ba4f9b19-ed9d-11e4-9118-bcaec565249c.html
- FEDORA-2015-6790 : Fedora 20 Update: wordpress-4.2.2-1.fc20
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158278.html
FEDORA-2015-6808 : Fedora 21 Update: wordpress-4.2.2-1.fc21
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158271.html
- DLA 236-1 : wordpress security update
https://lists.debian.org/debian-lts-announce/2015/06/msg00000.html
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
XSS - Prevention - POST : suspicious tag with event found in data
5.0.0
     


 
 
 
 
 Risk level 
Moderate 

 Vulnerability First Public Report Date 
2015-04-26 

 Target Type 
Server 

 Possible exploit 
Remote