Get Expert Website Hosting

Choose website reliability and expertise with SiteGround!

WordPress

WordPress 4.2.3 Security Update Applied

Jul 24, 2015 1 min read Hristo Pandjarov

cover-photo The latest WordPress update is live since yesterday. For those of you who have opted in to our AutoUpdater or have enabled the WordPress internal system for automatic updates it should be now ready to use! Check out the official release notes for detailed information about the update and read on to see what we’ve done to further protect our customers.

It’s a Security Update

Although WordPress 4.2.3 addresses more than 20 bugs from the previous versions of the application, as usual, its focus remains on the security issues it has fixed. As stated in the official release post:

WordPress versions 4.2.2 and earlier are affected by a critical cross-site scripting vulnerability, which could allow anonymous users to compromise a site.

This is why we’ve taken two steps to protect our customers:

  1. Zero-day Update: all of you who have subscribed to our AutoUpdater received the update immediately after its release
  2. Special WAF Protection: our own security team has assembled a special rule for our application firewall that will protect those of you who have not been updated to the latest version.

This WAF method is proven to be the safest and least intrusive way to protect you from any potential hacks without any modification to your content. However, we strongly recommend that you update to the latest WordPress version – our security rules only shield you from hacking attempts, but do not patch the security holes in your site!

Share this article

Hristo Pandjarov

Product Innovation Director

Enthusiastic about all Open Source applications you can think of, but mostly about WordPress. Add a pinch of love for web design, new technologies, search engine optimisation and you are pretty much there!

More by Hristo

Related Posts

Improved SiteGround Email Marketing Tool, Now With Lead Generation Plugin for WordPress

Crafting a successful online presence is an on-going process. From curating engaging content to showcasing your…

  • Sep 12, 2023
  • 2 min read

WCUS 2023 In a Nutshell

As an organizer of WordCamp US 2023, I am overjoyed with how the event turned out.…

  • Aug 29, 2023
  • 6 min read

How to Get Ready for WordCamp USA 2023

Welcome to my series about life at a major WordCamp! My name is David Wolfpaw, and…

  • Aug 21, 2023
  • 4 min read

Comments ( 1 )

author avatar

Leho Kraav @lkraav

Jul 24, 2015

@hristo there's a pretty big s***storm over how core changed the shortcode api in 4.2.3 seemingly overnight and broke *a lot* of sites. ​https://core.trac.wordpress.org/ticket/15694 ​https://core.trac.wordpress.org/ticket/33102

Reply

Leave a comment