WordPress Patches Critical Flaw Enabling Code Execution on Some Servers
WordPress released version 7.1.2 on September 22 to fix a critical core flaw that lets an unauthenticated attacker make a site load a PHP file from outside its theme folders. On some servers this can escalate to running attacker code. Fixes shipped for every supported branch back to 4.7.
- Patch released September 22 in WordPress 7.1.2
- Flaw lets sites load a PHP file outside theme folders
- On some servers it allows arbitrary code execution
- Fixes cover all branches back to 4.7
Read next
Security