Security experts at Wordfence reported that zero-Day vulnerabilities in three different WordPress plugins have been exploited in the wild. The flaws have been classified as critical PHP object injection issues, they affect the Appointments, Flickr Gallery, and RegistrationMagic-Custom Registration Forms plugins. The impact of the issues is limited because the number of WordPress installs using them is modest. WordPress, as many other organizations, has been running a bug bounty program since May 2017 that already allowed to find many vulnerabilities in the popular CMS.”]
Source: http://securityaffairs.co/wordpress/63783/hacking/wordpress-zero-day-flaws.html

