WordPress Releases Security Update

Original release date: August 04, 2015

WordPress 4.2.3 and prior versions contain critical cross-site scripting and potential SQL injection vulnerabilities. Exploitation of these vulnerabilities could allow a remote attacker to take control of an affected website.

Users and administrators are encouraged to review the WordPress Security and Maintenance Release and upgrade to WordPress 4.2.4.


This product is provided subject to this Notification and this Privacy & Use policy.

CVE-2001-1594 (entegra_p&r_firmware)

GE Healthcare eNTEGRA P&R has a password of (1) entegra for the entegra user, (2) passme for the super user of the Polestar/Polestar-i Starlink 4 upgrade, (3) 0 for the entegra user of the Codonics printer FTP service, (4) eNTEGRA for the eNTEGRA P&R user account, (5) insite for the WinVNC Login, and possibly other accounts, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

CVE-2003-1603 (discovery_vh)

GE Healthcare Discovery VH has a default password of (1) interfile for the ftpclient user of the Interfile server or (2) “2” for the LOCAL user of the FTP server for the Codonics printer, which has unspecified impact and attack vectors.