Skip to main content

WordPress SQL Injection Vulnerability Patched

WordPress has recently released patch 4.8.3 to fix an SQL injection security vulnerability. This vulnerability concerned an exploit in which a line of malicious code could create queries with the potential to perform SQL injection-based attacks, potentially allowing attackers to hijack entire websites.

Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

WordPress has recently released patch 4.8.3 to fix an SQL injection security vulnerability. This vulnerability concerned an exploit in which a line of malicious code could create queries with the potential to perform SQL injection-based attacks, potentially allowing attackers to hijack entire websites.


Affected platforms

The following platforms are known to be affected:

Threat details

This vulnerability concerned an exploit in which a line of maliciouscode could create queries with the potential to perform SQL injection-based attacks, potentially allowing attackers to hijack entire websites. Whilst injection can be severe for website owners, particularly with the potential for site hijacks, the attack has been patched. Users will remain vulnerable if they have not updated, however automatic updates are enabled by default so the number of users remaining should be low.


Remediation steps

Type Step

Upgrade to WordPress version 4.8.3


Last edited: 15 December 2021 9:45 am