WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.

On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up

AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up AI has changed how fast attacks move. Work that once took an attacker days now

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six

Russia’s businesses under strain from Ukraine’s attacks on Wildberries

Russia’s businesses under strain from Ukraine’s attacks on Wildberries Source: Hacker News