• Latest
WordPress patches critical flaw enabling site takeover — Arabian Post

WordPress patches critical flaw enabling site takeover — Arabian Post

July 18, 2026

Which day is best for flight booking? Travel expert shares tips for finding cheaper airfares

August 23, 2026

Empat dicekup, salah guna permit gali pasir buat lombong emas

August 23, 2026

Iran warns nearby nations against joining US ‘economic war’ efforts | Conflict News

August 23, 2026

The world loves boiled and salted edamame. But how about sweet?

August 23, 2026

Nine years away, Hull City return to EPL with a bang by stunning Manchester United

August 23, 2026

North Delhi Strikers defend 141 to beat South Delhi Superstarz by 10 runs, go top of Women’s DPL 2026 table

August 23, 2026

Islamabad chief commissioner moves SC for early hearing of plea against Imran’s hospital transfer order

August 23, 2026

One dead, nine injured after vehicle carrying Indian nationals overturns in Oman’s Haima

August 23, 2026

Four kites cross from Gaza Strip into Israel

August 22, 2026

Nanda Malini bids farewell to the nation – Sri Lanka Mirror – Right to Know. Power to Change

August 23, 2026

3 FIRs Against 14 Named, 200+ Unidentified Job Aspirants After Police Clash

August 22, 2026

Responders fight spreading wildfire in Indonesia’s Way Kambas Park

August 23, 2026
Sunday, August 23, 2026
  • About us
  • Advertise with us
  • Submit Articles
  • Privacy Policy
  • Contact us
Asia Today
No Result
View All Result
Subscribe
  • Login
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
No Result
View All Result
Morning News
No Result
View All Result
Home Western Asia United Arab Emirates

WordPress patches critical flaw enabling site takeover — Arabian Post

by Asia Today Team
July 18, 2026
in United Arab Emirates
Reading Time: 3 mins read
21 0
A A
0
WordPress patches critical flaw enabling site takeover — Arabian Post
24
SHARES
303
VIEWS
Share on FacebookShare on Twitter

READ ALSO

Sounds of the East Illuminate the Historic Central European City — Arabian Post

Objective Digital Psychological Assessment Launches in Singapore, Offering Clarity for Inattention and Hyperactivity Concerns — Arabian Post


WordPress has issued emergency safety updates to dam a vital vulnerability that allowed unauthenticated attackers to execute code on web sites working normal installations with out plugins.

The flaw, dubbed “wp2shell” and tracked as CVE-2026-63030, affected WordPress 6.9.0 by 6.9.4 and variations 7.0.0 and seven.0.1. WordPress launched variations 6.9.5 and seven.0.2 on July 17, urging directors to put in the patches instantly.

The vulnerability carried distinctive threat as a result of an attacker didn’t require a legitimate account, administrator privileges or consumer interplay. A specifically ready nameless request might exploit weaknesses within the WordPress REST API and doubtlessly run arbitrary code on the underlying server.

Profitable exploitation might give an intruder management over a web site, its database and saved data. Attackers might alter pages, steal credentials, implant malicious software program, redirect guests or use compromised servers to launch additional assaults.

WordPress activated pressured updates by its automatic-update system due to the severity of the problem. Web sites that help automated background updates ought to obtain the patched launch, though directors have been suggested to confirm the model put in reasonably than assume the method has accomplished efficiently.

The vulnerability arose from confusion within the dealing with of REST API batch routes, mixed with an SQL injection situation that would result in distant code execution. The affected part permits a number of REST API requests to be processed collectively, enhancing effectivity for purposes interacting with WordPress.

Safety researcher Adam Kues, working with Assetnote and Searchlight Cyber, recognized the flaw and reported it privately in order that fixes may very well be ready earlier than technical particulars had been made public. The difficulty was assigned a vital severity score as a result of exploitation was potential over a community with low complexity and with out authentication.

A inventory WordPress set up may very well be weak even when no third-party themes or plugins had been put in. That attribute distinguishes wp2shell from many widespread WordPress compromises, which generally exploit poorly maintained extensions reasonably than the platform’s core software program.

WordPress 6.9 was affected by each the vital remote-code-execution vulnerability and a separate high-severity SQL injection flaw, tracked as CVE-2026-60137. Model 6.9.5 incorporates fixes for each points. WordPress 6.8 was affected solely by the separate SQL injection drawback and has been patched by model 6.8.6.

Variations launched earlier than WordPress 6.8 should not affected by both of the newly disclosed vulnerabilities. Nonetheless, operators utilizing older branches nonetheless face safety dangers arising from unsupported software program and beforehand disclosed flaws. WordPress maintains that solely its latest launch receives full lively help.

The beta model of WordPress 7.1 was additionally affected. Builders and testing groups utilizing that department have been directed to maneuver to WordPress 7.1 Beta 2, which incorporates the required fixes. Manufacturing web sites should not alleged to run beta software program.

The replace modifies three core information related to REST API processing and database queries: class-wp-rest-server. php, class-wp-query. php and rest-api. php. No WordPress packages had been revised as a part of the safety launch.

WordPress is used throughout an unlimited vary of internet sites, from private blogs and small companies to information platforms, on-line outlets and authorities portals. Estimates place its world footprint at lots of of tens of millions of websites, magnifying the potential influence of a core vulnerability that may be exploited with out credentials.

Web site house owners ought to verify that their installations now present WordPress 7.0.2, 6.9.5 or one other unaffected model. Directors working the 6.8 department ought to improve to a minimum of 6.8.6 due to the accompanying SQL injection repair.

Operators unable to replace mechanically can set up the discharge by the Dashboard’s Updates part. Managed internet hosting clients ought to confirm whether or not their supplier has utilized the patch, significantly when replace controls are dealt with centrally.

Safety groups have additionally suggested directors to look at server entry logs, sudden administrator accounts, unfamiliar scheduled duties and adjustments to core information. Unexplained redirects, injected scripts or newly created PHP information could point out compromise.



Source link

Tags: ArabiancriticalEnablingflawpatchesPostsitetakeoverWordPress

Related Posts

United Arab Emirates

Sounds of the East Illuminate the Historic Central European City — Arabian Post

August 22, 2026
United Arab Emirates

Objective Digital Psychological Assessment Launches in Singapore, Offering Clarity for Inattention and Hyperactivity Concerns — Arabian Post

August 22, 2026
United Arab Emirates

MyRepublic expands GAMER lineup with Dreamcore x MyRepublic RTX 5060 Ti Gaming PC and Limited Edition ASUS T1 Graphics Card Broadband Bundle

August 21, 2026
United Arab Emirates

Tonglu Enhances Regional Tourism Strategy Through Immersive Experiences and Infrastructure Upgrades — Arabian Post

August 20, 2026
United Arab Emirates

Medusa ransomware breaches more than 500 organisations — Arabian Post

August 20, 2026
United Arab Emirates

Oil prices climb as Iran tensions deepen — Arabian Post

August 19, 2026
Asia Today

Copyright © 2022 Asia Today.

Navigate Site

  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • DMCA
  • Terms and Conditions
  • Contact us

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Homepages
  • World
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Sri Lanka
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • Opinion
  • Politics
  • Business
  • Entertainment
  • Fashion
  • Food
  • Health
  • Lifestyle
  • Science
  • Tech
  • Travel
  • Sports
  • About us
  • Advertise with us
  • Privacy Policy
  • Contact us
  • Support AsiaToday

Copyright © 2022 Asia Today.