Blog | G5 Cyber Security

Zero-day Content Injection Vulnerability found in WordPress

A new dangerous zero-day Content Injection vulnerability has been discovered in the WordPress CMS. The vulnerability affects the REST API that was recently put into widespread use across WordPress sites with the introduction of official API endpoints in version 4.7.1. At least 18 million websites run the popular WordPress CMS, roughly 26% of the top 10,000 websites are running the CMS. Experts at Sucuri did not provide technical details about the flaw to prevent that crooks can exploit the flaw in the wild.”]

Source: https://securityaffairs.co/wordpress/55892/hacking/wordpress-zero-day-content-injection.html

Exit mobile version