Major Vulnerability Hits WordPress

LOS ANGELES — A vital security warning has been issued to the many users of self-hosted WordPress installations — a user base that includes countless adult websites.

In addition to affecting WordPress users, the exploit, which employs an XML Quadratic Blowup Attack, also affects users of the Drupal platform, which while relatively popular, does not have the vast market share of the Open Source WordPress solution — which may be adult entertainment’s most widely used content management system (CMS) and publishing platform.

As an example of the platform’s overall reach, recent World Wide Web Consortium (WC3) statistics reveal that 23 percent of today’s web is powered by WordPress.

The exploit is capable of immediately crashing a website, by causing complete usage of available CPU power and memory, while also causing a Denial of Service attack on the software’s MySQL database — but fortunately, this attack can be defeated by simply updating the software to its latest version.

The WordPress security team has now released the WordPress 3.9.2 system update and is strongly encouraging users to update their sites immediately. The Drupal security team has likewise issued a fix and also recommends users immediately update to its latest version.

The exploit was discovered by Salesforce.com security expert Nir Goldshlager, who explains that this attack inflates a small XML document of several hundred kilobytes into multiple gigabytes, crushing any Apache server in a matter of moments.

“If an attacker defines the entity ‘&x;’ as 55,000 characters long, and refers to that entity 55,000 times inside the ‘DoS’ element, the parser ends up with an XML Quadratic Blowup attack payload slightly over 200 KB in size that expands to 2.5 GB when parsed,” Goldshlager says. “This expansion is enough to take down the parsing process.”

Goldshlager has released a video demonstrating the attack in action.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

New EU User Stats Could Reclassify Major Adult Sites Under DSA

Three high-traffic adult sites previously classified as “very large online platforms” under the European Union’s Digital Services Act are reporting user numbers below the threshold for that label, opening the way for possible downgrading of their obligations under that law.

Spicerack Launches 'SpicyFanz' Creator Monetization Platform

Adult product marketplace Spicerack Market has launched its SpicyFanz creator monetization platform.

Singapore Livestreamer Jailed for Performing 'Obscene Acts' in Public

A judge in Singapore on Thursday sentenced a Vietnamese woman to three weeks in jail for livestreaming “obscene acts” from a public area.

FSC Withdraws Support for North Dakota AV Bill

The Free Speech Coalition (FSC) has withdrawn its support for an age verification bill in North Dakota, following changes made by the state legislature.

APClips Launches New Blog

APClips has launched a blog, AmateurPorn.com.

Centrobill Launches 'Max' Payment Suite

Payment processing service Centrobill has launched its new Max Suite toolkit.

AEBN Publishes Popular Searches by Country for December, January

AEBN has released the list of popular searches from its straight and gay theaters by country in December and January.

South Dakota Legislators Debate AV Legal Strategies

The South Dakota state Senate Judiciary Committee on Tuesday heard testimony and debate over two competing age verification bills, in a hearing that focused largely on which piece of legislation could best withstand potential legal challenges.

Mobile OnlyFans Management Platform 'TopCreator' Launches

Mobile OnlyFans management and chat platform TopCreator has launched.

JustFor.fans Marks Its 7th Anniversary With Palm Springs Conference

JustFor.fans is celebrating its seventh anniversary with a four-day conference and party in Palm Springs May 18-21.

Show More