WordPress 6.4.2 Patches Serious Security Vulnerability

Báo Thanh niênBáo Thanh niên12/12/2023


According to The Hacker News, WordPress has released version 6.4.2, which patches a serious security vulnerability that could be exploited by hackers in combination with another bug to execute arbitrary PHP code on websites that still have the vulnerability.

The remote code execution vulnerability is not directly exploitable in the core, but the security team feels it has the potential to cause a high severity vulnerability when combined with certain plugins, especially in multisite installations, the company said.

According to security firm Wordfence, the issue stems from a class introduced in version 6.4 to improve HTML parsing in the block editor. Through this, an attacker could exploit the vulnerability to inject PHP objects contained in plugins or themes to execute arbitrary code and gain control of the target website. As a result, the attacker could delete arbitrary files, retrieve sensitive data, or execute code.

WordPress 6.4.2 vá lỗ hổng tấn công từ xa nghiêm trọng - Ảnh 1.

As a popular content management platform, WordPress is also a target for hackers to exploit.

In a similar advisory, Patchstack said an exploit chain was found on GitHub as of November 17 and added to the PHP Common Utility Chains (PHPGGC) project. Users should manually check their websites to ensure they have updated to the latest version.

WordPress is a free, easy-to-use, and globally popular content management system. With easy installation and extensive support, users can quickly create all kinds of websites from online stores, portals, discussion forums...

According to data from W3Techs, WordPress will power 45.8% of all websites on the internet in 2023, up from 43.2% in 2022. That means more than 2 out of every 5 websites will be powered by WordPress.



Source link

Comment (0)

No data
No data

Same tag

Same category

Colorful Vietnamese landscapes through the lens of photographer Khanh Phan
Vietnam calls for peaceful resolution of conflict in Ukraine
Developing community tourism in Ha Giang: When endogenous culture acts as an economic "lever"
French father brings daughter back to Vietnam to find mother: Unbelievable DNA results after 1 day

Same author

Image

Heritage

Figure

Business

No videos available

News

Ministry - Branch

Local

Product