WordPress 5.8.1 Released to Fix Multiple Vulnerabilities
WordPress announced a security and maintenance release, version 5.8.1. It is important to update WordPress, especially versions 5.4 to 5.8 in order fix three security issues.
WordPress 5.8.1 Security and Maintenance Release
It’s not uncommon for WordPress or any software for that matter to publish a bug fix update following a major version update in order to fix unforeseen issues as well as introduce improvements that didn’t make it in time for the major release.
In WordPress those updates are called a maintenance release.
This update also includes a security update, which is somewhat uncommon for the WordPress core. That makes this update more important than the typical maintenance release.
WordPress Security Issues Fixed
WordPress 5.8.1 fixes three vulnerabilities:
- A data exposure vulnerability within the REST API
- Cross-Site Scripting (XSS) vulnerability in the Gutenberg block editor
All three of the above vulnerabilities are so concerning that the WordPress announcement recommends immediately updating WordPress installations.
REST API Vulnerability
The WordPress REST API is an interface that allows plugins and themes to interact with the WordPress core.
The REST API has been a source of security vulnerabilities, including most recently with the Gutenberg Template Library & Redux Framework vulnerability that affected over a million websites.
This vulnerability is described as a data exposure vulnerability, which means that sensitive information could be revealed. There are no other details at this time regarding what kind of information but it could be as severe as passwords to data that could be used to mount an attack through another vulnerability.
WordPress Gutenberg XSS Vulnerability
Cross-Site Scripting (XSS) vulnerabilities happen relatively frequently. They can happen whenever there is a user input like a contact or email form, any kind of input that is not “sanitized” to prevent the upload of scripts that can trigger unwanted behavior in the WordPress installation.
The Open Web Application Security Project (OWASP) describes the potential harm of XSS vulnerabilities:
“An attacker can use XSS to send a malicious script to an unsuspecting user. The end user’s browser has no way to know that the script should not be trusted, and will execute the script.
Because it thinks the script came from a trusted source, the malicious script can access any cookies, session tokens, or other sensitive information retained by the browser and used with that site. These scripts can even rewrite the content of the HTML page.”
This specific vulnerability affects the Gutenberg block editor.
The latest and safest version is Lodash 4.17.21.
The U.S. Homeland Security sponsored CVE List website details the vulnerability:
“Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.”
There appear to be many other vulnerabilities affecting the Lodash library in the 4.1.7 branch as well.
WordPress Urges Immediate Updating
These security vulnerabilities add a sense of urgency to this update. All publishers are recommended by WordPress to update.
The official WordPress announcement recommends updating:
“Because this is a security release, it is recommended that you update your sites immediately. All versions since WordPress 5.4 have also been updated.”
Best and Cheap WordPress 5.8.1 Hosting
The hosting provider that we mean is ASPHostPortal. Who and why ASPHostPortal? ASPHostPortal is one of the best web hosting in the world. Founded in 2008, this company managed by a strong team of web hosting experts. Here are several reasons why you can choose them as your WordPress hosting partner. To make it clear, we have worked out a comprehensive review of the feature, performance, customer service and pricing of this service.
Respected By The WordPress Community
ASPHostPortal is well-respected in the WordPress community, especially for their quick, helpful support. All hosting companies have good and bad customer experiences on the web review, but if you look at ASPHostPortal’s review mentions the majority of feedback is positive.
From HostingAdvice (https://hostadvice.com/hosting-company/asphostportal-com-reviews/)
From WHTOP (https://www.whtop.com/review/asphostportal.com)
From Trustpilot (https://www.trustpilot.com/review/asphostportal.com)
Engineered For Speed
ASPHostPortal shared hosting ($3.81/month) is good. The speed depends on which plan you choose but each one comes with top-notch hardware, CDN, SuperCacher, and software for it’s a tier. ASPHostPortal also makes constant updates to improve speed – allowing customer sites to load even faster. This is our test result from GTMetrix, the loaded time is 0.7 second only.
Best Support In The Industry
With ASPHostPortal’s support system we have always been able to reach someone within minutes whether it be through 24/7 ticket. That’s because ASPHostPortal is a people-focused company who won’t make you wait around listening to bad elevator music. Their team is so helpful and will honestly bend over backward to make sure your issues are resolved. And they won’t tell you “it’s not a hosting-related problem” like other hosting companies.
Not only will your site be protected through auto-updates, daily backups, and server protection, but ASPHostPortal also releases their own patches when there’s a widespread security vulnerability (with WordPress, or even a specific WordPress plugin). They’re both proactive AND reactive which is good because WordPress sites have become prime targets.
ASPHostPortal WordPress Hosting Plans
Whether you’re on a $3.81/month budget or you need a $12.99/month dedicated server, there’s a plan for everyone. I mentioned this already but I use their plan and my WordPress site loads in under 1 second.
Conclusion – ASPHostPortal Is Awesome For WordPress Hosting
Between their hosting and tech support, ASPHostPortal is a clear winner. I don’t write many articles on the other hosting companies because ASPHostPortal is in my opinion, the best. I do WordPress SEO and speed optimization for a living so I’ve been through a lot of hosts – and I’m just glad I found one who I can stick with and keep my website blazing fast.