| |
A WordPress vulnerability scored 9.2/10 is present in all versions since 2016
A critical WordPress vulnerability (CVSS 9.2/10) affecting all versions since 2016 allows unauthenticated attackers to exploit path traversal in page-template resolution to potentially achieve remote code execution. The vulnerability requires specific preconditions, including themes with directories named starting with "page-" (affecting popular themes like Neve, Hestia, and Sydney) and readable PHP files on the server. WordPress has released patches across all affected versions from 4.7 onwards, with version 7.1.2 containing the fix.
Read Full Article →
← More Tech news