⟳ Репост от kat, ghost of helenruthsghost

Hey folks. If you've got a WordPress site, you need to check what version you're on. There's a critical vulnerability for versions 6.9.0 to 7.0.1. Update immediately. Like put your phone down now & do it. Not tomorrow. Complete compromise & remote code execution are possible w a simple script

Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress CoreThreat actors are actively exploiting two vulnerabilities in WordPress Core. The vulnerabilities carry a combined CVSS score of 9.8 out of 10.businessinsights.bitdefender.com