New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
A Critical WordPress Vulnerability Allows Hackers to Inject Malicious PHP Code, Leaving Millions of Websites Exposed A newly discovered pre-authentication cross-site scripting (XSS) vulnerability in WordPress has been found to allow hackers to inject malicious PHP code on affected websites. The flaw, which affects all versions of WordPress prior to 5.8.3, enables attackers to bypass … Read more