Recent WordPress exploit. Update to the latest version, 4.2.1, NOW!

This has affected many of the most popular WordPress themes and plugins. A comprehensive review is currently taking place to ensure that issues with the affected ones are being resolved.
According to Gary Pendergast, who is assisting in resolving this, “There is no official headcount on how many plugins are affected, as it’s a case-by-case thing to check.” He has also indicated that some of the affected plugins no longer have automated updates, stating, “Jetpack, EDD, P3, Download Monitor and Related Posts for WP opted-in for auto-updates; I didn’t keep track of who opted out.”
When was this issue discovered, and who was affected?

As I said, not all affected themes and plugins have been determined. We have listed several identified below; however, this still needs to be completed.
- Gravity Forms
- WP E-Commerce
- WP Touch
- WordPress SEO
- Updraft Plus
- Google Analytics by Yoast
- Jetpack
- All-in-One SEO
- Easy Digital Downloads
- My Calendar
- Ninja Forms
These represent a few of the affected themes and plugins, so if you do not see one you have used on the list, that does not mean it wasn’t a concern. As more research is completed, additional plugins will be identified.
Issues that cause vulnerability are not uncommon; they are more common than most people realize. What is important is that information is shared with the user and that the information needed to protect the user from vulnerabilities is shared.
What is being done to solve this issue?
The WordPress.org team has scrambled to investigate the issue and has released a critical security update, WordPress 4.2.1. This update has been rolled out as an automatic background update for websites enabling this function.
What if I am a developer and I have yet to be contacted?
Suppose you have been using the information provided in the WordPress Codex to develop functions that would correctly escape user input. In that case, you may have added incorrect coding, meaning you could also share the XSS vulnerability. The inaccurate information in the Codex was created in 2009, which means it is possible that you could have entered the wrong coding. First, please check whether you use the functions add_query_arg() and remove_query_arg() in your theme or plugin. If so, you will need to escape the output using one of the following functions:
- If you are using the add_query_arg() or remove_query_arg() in an HTTP header or location redirect, you will need to use esc_url_raw() to escape the output
- If you are using it as a link in printed materials, you will want to use the esc_url()
This information is laid out by Gary Prendergast’s post on the make.wordpress.org page, and it provides the steps needed to escape the output. By making these changes, you can resolve the vulnerabilities created by the original errors.
What if I am not a developer?
You should do that first if you haven’t updated your site to the latest WordPress version. This is critical because keeping your site up to date will help you maintain a secure site. When you purchase new themes and plugins, make sure that you check to see if there are any additional updates you need to load.
Also, look at who has access to your site. Ensure that the people with admin access are the only people you trust and who need it. Don’t overload your site with unnecessary themes and plugins; use only what you need. This will make managing the security of the themes and plugins you need easier. Make your passwords strong with this tool.
You should also regularly scan your site to see if any threats or issues arise, as regular scanning can prevent future problems. Could you make sure that you have a robust prevention system in place? While it may be costly on the front end, the savings from good prevention will pay off in the long run. New threats emerge daily, and prevention is the best defense; your site should be well protected. Think of your site as your business, then defend it. Take the steps to ensure that your site is protected by engaging the proper professional.
Maintenance Package with PX Media.

Feel free to give us a call and get a free quote.
626.768.0760
Frequently Asked Questions
What are the most critical recent WordPress threats?
How did attackers exploit the Post SMTP vulnerability?
A broken access control in the plugin’s REST API let low level users access sensitive data, including admin password reset emails, enabling them to hijack websites.
What happened with the Gravity Forms plugin?
During a supply chain attack, the installer file was compromised with malware that enabled remote code execution and unauthorized admin account creation. The vulnerability existed only in manual downloads auto updates were unaffected.
Why are WordPress plugins and themes frequent targets?
What proactive steps should site owners take to stay secure?
Why are virtual firewall patches (vPatches) helpful?
How widespread are WordPress vulnerabilities?
Why is excessive use of themes/plugins risky?
Why is frequent scanning important?
What does PX Media recommend for WordPress security?
Turn Recent WordPress exploit. Get Up To Speed, Securing WordPress into a clearer next step
Recent WordPress exploit. Get Up To Speed, Securing WordPress becomes more useful when the takeaway is connected to WordPress design support, website clarity, and measurable lead quality. PX Media can turn Recent WordPress exploit. Get Up To Speed, Securing WordPress into a practical review of layout, navigation, forms, calls to action, speed, mobile experience, content clarity, and tracking so the next move supports the business instead of adding more noise.
WordPress Design Experts
Recent WordPress exploit. Get Up To Speed, Securing WordPress pairs well with WordPress Design Experts when you want a clearer next move before changing campaigns, design, or measurement.
Pasadena WordPress Design Company
Pasadena WordPress Design Company gives Recent WordPress exploit. Get Up To Speed, Securing WordPress a stronger follow-through path for planning, service review, and practical action.
Local Digital Marketing Agency
Local Digital Marketing Agency can connect the ideas around Recent WordPress exploit. Get Up To Speed, Securing WordPress with a more focused service conversation.
Blog & Press
Recent WordPress exploit. Get Up To Speed, Securing WordPress often leads into Blog & Press when the goal is better clarity, cleaner tracking, or stronger lead quality.
Talk To Us
Talk To Us can help turn the takeaways from Recent WordPress exploit. Get Up To Speed, Securing WordPress into a more specific plan for your business.
Questions that come up after Recent WordPress exploit. Get Up To Speed, Securing WordPress
How does Recent WordPress exploit. Get Up To Speed, Securing WordPress fit into a practical WordPress design support plan?
Recent WordPress exploit. Get Up To Speed, Securing WordPress can help clarify where WordPress design support needs more attention, especially around content hierarchy, mobile usability, speed, conversion flow, and clear service messaging. With Recent WordPress exploit. Get Up To Speed, Securing WordPress as the starting point, PX Media shapes next steps that are easier to measure and easier for visitors to act on.
What should a business review before acting on Recent WordPress exploit. Get Up To Speed, Securing WordPress?
Before making changes after Recent WordPress exploit. Get Up To Speed, Securing WordPress, it helps to review layout, navigation, forms, calls to action, speed, mobile experience, content clarity, and tracking. That keeps decisions around Recent WordPress exploit. Get Up To Speed, Securing WordPress grounded in real visitor behavior, lead quality, and the business outcome that matters most.
When is it worth asking PX Media for help after Recent WordPress exploit. Get Up To Speed, Securing WordPress?
It is worth asking for help when the issue behind Recent WordPress exploit. Get Up To Speed, Securing WordPress feels scattered, hard to measure, or disconnected from qualified inquiries. PX Media can review the current setup and help turn Recent WordPress exploit. Get Up To Speed, Securing WordPress into a clearer action plan.
Need help applying Recent WordPress exploit. Get Up To Speed, Securing WordPress?
PX Media can review the current setup behind Recent WordPress exploit. Get Up To Speed, Securing WordPress, clarify the strongest opportunity, and connect WordPress design support with a cleaner plan for visibility, conversion, and follow-up.

