The record
Written from the 1 report below. Nothing here is unsourced.
- WordPress has patched a critical vulnerability that allows attackers to load arbitrary PHP files from outside intended directories without authentication.
- The flaw affects all versions from 4.7.0 through 7.1.1 and requires an immediate update to version 7.1.2 or later.
- Successful exploitation is dependent on specific server and theme configurations rather than occurring on every instance.
- Applying the latest software update is the only recommended remediation for this security issue.
What to watch next
- Availability of exploit code
- Reports of in-the-wild exploitation
- Monitoring the CISA Known Exploited Vulnerabilities catalog
Coverage1
1 report
English national1
All filed from India
Named United States · Patchstack · Robert Ressl · Wordpress
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
