
More improvements to Attack Surface Custom Policies
Tl;dr We’ve made a few improvements to Attack Surface Custom Policies, such as viewing alerts more easily and deleting custom policies. We’ve also made a …

Detectify Admin
![[Alert] New WordPress XSS Vulnerability Discovered](/_next/image/?url=https%3A%2F%2Fblog-detectify-api.stage.io-ext.se%2Fapp%2Fuploads%2F2022%2F11%2Fwordpress-logo-notext-rgb2.png&w=3840&q=75)
Are you running WordPress 4.2.0 to 4.5.1? Time to upgrade to 4.5.2!
It was recently discovered that WordPress versions 4.2.0 to 4.5.1 are vulnerable against a reflected XSS vulnerability in a specific WordPress SWF-file: flashmediaelement.swf. The vulnerability could lead to leaked WordPress credentials, or be used as a stepping stone to more severe attacks.
3 things you can do to protect your website:
As always, we recommend you to run regular security tests on your website to keep up with all the latest vulnerabilities.
Stay safe!

Tl;dr We’ve made a few improvements to Attack Surface Custom Policies, such as viewing alerts more easily and deleting custom policies. We’ve also made a …

Validate security policies like you mean it Not everything on your attack surface is a vulnerability. Every organization has their own internal security policies that …