DavidFuhr’s avatarDavidFuhr’s Twitter Archive—№ 235

  1. #wordpress 4.2 allows stored #xss in comments: seclists.org/fulldisclosure/2015/Apr/84 Upgrade to 4.2.1 immediately wordpress.org/news/2015/04/wordpress-4-2-1/