ArchLinux: 201509-7: wordpress: multiple issues
Summary
- CVE-2015-5714 (cross-side scripting)
A cross-site scripting vulnerability has been discovered when processing
shortcode tags.
- CVE-2015-5715 (permission bypass)
It has been discovered that users without proper permissions could
publish private posts and make them sticky.
Resolution
Upgrade to 4.3.1-1.
# pacman -Syu "wordpress>=4.3.1-1"
The problem has been fixed upstream in version 4.3.1.
References
https://wordpress.org/news/2015/09/wordpress-4-3-1/ https://access.redhat.com/security/cve/CVE-2015-5714 https://access.redhat.com/security/cve/CVE-2015-5715 https://bugs.archlinux.org/task/46340
Workaround
None.