WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.

On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication Read on The Hacker News Source: The Hacker News

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to

Are we offloading too much of our thinking to AI?

Are we offloading too much of our thinking to AI? Source: Hacker News