WordPress force installs Jetpack security update on 5 million sites

WordPress force installs Jetpack security update on 5 million sites


Automattic, the company behind the WordPress content management system, force deploys a security update on over five million websites running the Jetpack WordPress plug-in.


Jetpack is a remarkably popular WordPress plug-in that provides free security, performance, and website management features, including brute-force attack protection, site backups, secure logins, and malware scanning.


The plugin has more than 5 million active installations, and it is developed and maintained by Automattic, the company behind WordPress.





No in the wild exploitation


The vulnerability was found in the Carousel feature and its option to display comments for each image, with nguyenhg_vcs being the one credited for responsibly disclosing the security bug.


No other details are available regarding this security flaw to protect the sites that haven't yet been updated. However, we do know that Automattic addressed it with added authorization logic.


The announcement made by Automattic says the bug impacts all versions starting with the Jetpack 2.0 release and going back to November 2012.


The Jetpack development team added that it found no evidence that the vulnerability has been exploited in the wild.


"However, now that the update has been released, it is only a matter of time before someone tries to take advantage of this vulnerability," the developers warn.



Jetpack patch

Automattic is force installing patched versions on all websites running vulnerable Jetpack versions, with most sites already having been updat ..

Support the originator by clicking the read the rest link below.