WordPress: Unauthenticated path traversal leading to conditional RCE
AI summary · glm-5.3
WordPress advisory discloses an unauthenticated path traversal in core that can lead to conditional remote code execution.
A WordPress core security advisory (GHSA-7hp8-65ch-5whp) published on the wordpress-develop GitHub repository describes an unauthenticated path traversal vulnerability that can lead to conditional remote code execution. The advisory gained traction on Hacker News (25 points, 11 comments). The available text does not state a CVE id, affected versions, or observed exploitation.
- Unauthenticated path traversal in WordPress core enables conditional RCE
- Disclosed via GitHub advisory GHSA-7hp8-65ch-5whp
- WordPress is ubiquitous, so unpatched sites warrant prompt updating
OrganizationsWordPress
Full article
25 points · 11 comments on Hacker News
This source does not provide full text. Read it at github.com.