FlashFeed
๐Ÿ’ป
๐Ÿ’ป Technology

Critical WordPress flaw up to v7.0.3 lets attackers gain admin access without an account

A critical pre-auth XSS vulnerability has been found in all WordPress versions up to 7.0.3, allowing an attacker without any user account to gain administrator privileges and execute arbitrary PHP code on the server. The flaw affects all installations regardless of installed plugins. The vulnerability was discovered with the help of AI.

Comments

No comments yet