WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
Overview
WordPress has addressed a serious vulnerability in its software that allows attackers to execute code on certain servers without needing an account. This flaw enables a malicious user to make a site load a PHP file from outside its theme folders, which can lead to unauthorized code execution. The fix was released on September 22, 2023, in version 7.1.2, and it applies to all supported versions of WordPress back to 4.7. Site owners are urged to update their installations promptly to protect against potential exploitation. This incident serves as a reminder of the importance of maintaining up-to-date software to secure websites from vulnerabilities.
Key Takeaways
- Affected Systems: WordPress core software, versions 4.7 and above
- Action Required: Update to WordPress version 7.
- Timeline: Disclosed on September 22, 2023
Original Article Summary
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners
Impact
WordPress core software, versions 4.7 and above
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Disclosed on September 22, 2023
Remediation
Update to WordPress version 7.1.2 or later
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability, Patch, Update, and 1 more.