-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2015.0039
         A critical vulnerability has been corrected in Wordpress
                               28 April 2015

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              WordPress
Operating System:     UNIX variants (UNIX, Linux, OSX)
                      Windows
Impact/Access:        Cross-site Scripting -- Remote with User Interaction
Resolution:           Patch/Upgrade
Member content until: Thursday, May 28 2015

OVERVIEW

        A critical vulnerability has been identified in WordPress prior to 
        version 4.2.1. [1]


IMPACT

        The vendor has provided the following details regarding the 
        vulnerability:
        
        "A few hours ago, the WordPress team was made aware of a cross-site 
        scripting vulnerability, which could enable commenters to compromise
        a site". [1]


MITIGATION

        The vendor strongly urges users to update to the latest version 
        immediately. [1]
        
        The vendor also states:
        
        "WordPress 4.2.1 has begun to roll out as an automatic background 
        update, for sites that support those".[1]


REFERENCES

        [1] WordPress 4.2.1 Security Release
            https://wordpress.org/news/2015/04/wordpress-4-2-1/

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBVT8YxhLndAQH1ShLAQJZZxAAmqky896Jbfa+xZWQKR4d6m8OM3cCJNS5
5VH0TnLR7P7avzG3VFczBln6R4fajuiSku0P0CmmS48X/85zT4CB67bbP/paYeTW
a1jjGe93mR/pccp4zeJE9R93Q81nnI7qRllkIEtFT1Kebgd3AGbjbqQAXcOWzvs8
ks/c7tCBeU8wg/iqkGrI8wqvvtwVibSXIdIM0yv/Ui7g1Y4N7uDFw2oFW6sIE+jf
Fqtu2LNTgKvCgv421Xv2WMAk0gil7H7wwTO+9N0TjvwoqeRb+J4ZCBrGfkwLAFbB
b9d8U5r4ZMh5eBIF6RXkpHF5ZU8IskiduX7dbIlzNFFhk651MhHjOA5hPnxZbdjd
PmYvs8M7A7euI/Mkltwey3T7SOhPOo6b5FcJ/VvdX+Wt8IwacGIp2qdJGjqLkUz8
UXCnsVDon9PC5qadjno73zxrn+vtcJqaH4ndV6BB6vgDXAI3klEs5gKg4v1/q/lb
eqmrF7OpMRjMXx0gCHSGysTLWhoMCnKZi/IT7zBCVKocZ5/CyAvNJlDv3gF5NJG9
TT8N2/aiPlMe0lGOkq03xZ7CZxWfVJhGISJTGQfPs1NORwiAIGiB6zJ9xOTZvMxB
0bUqR6E/1aloPteQmFuvzu3LJefIlQwPhbjJjGoZaS2Xb05Mrc5B0H1r+4DomP7P
LCsWDE4e6zE=
=b6WG
-----END PGP SIGNATURE-----