PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core
WordPress patched a critical unauthenticated path traversal that can enable PHP inclusion and RCE.
Wordfence warned that WordPress released fixes for a critical unauthenticated path traversal vulnerability in WordPress Core. The flaw can lead to local PHP file inclusion and, on affected server and theme configurations, remote code execution. Site owners are told to update immediately. The notice names no CVE and does not say the bug is being exploited.
- Unauthenticated path traversal affects WordPress Core.
- It can allow local PHP file inclusion.
- Some server and theme setups permit remote code execution.
- Wordfence urges an immediate WordPress Core update.
- No CVE or active exploitation is stated.
WordPress has released security updates for a critical unauthenticated path traversal vulnerability that can lead to local PHP file inclusion and, on affected server and theme configurations, remote code execution. Site owners should update WordPress Core immediately. The post PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core appeared first on Wordfence.
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at wordfence.com.