WordPress Multiple Vulnerabilities
RISK: High Risk
TYPE: Servers - Internet App Servers
Multiple vulnerabilities were identified in WordPress. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, sensitive information disclosure and data manipulation on the targeted system.
Note:
Proof-of-concept code is publicly available for CVE-2026-63030 and CVE-2026-60137. Attacker can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.
Impact
- Remote Code Execution
- Information Disclosure
- Data Manipulation
System / Technologies affected
- WordPress 6.8
- WordPress 6.9
- WordPress 7.1
Please refer to the link below:
https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
沒有留言:
發佈留言