LIVE · cybersecurity feed
Live wire

unauthenticated attack

wordpresscritical

WordPress Core Flaw Allows Unauthenticated Code Execution

A critical vulnerability in WordPress core allows unauthenticated attackers to execute arbitrary code on affected websites. The flaw, discovered by Adam Kues of Searchlight Cyber, impacted all sites running versions 6.9 and 7.0. WordPress has since released patches 6.9.5 and 7.0.2, and has enabled forced updates to protect all sites.