• Latest
WordPress patches critical flaw enabling site takeover — Arabian Post

WordPress patches critical flaw enabling site takeover — Arabian Post

July 18, 2026

Ridon dares Sara Duterte to attend Monday’s impeachment trial

September 12, 2026

9/11 at 25: How the ‘War on Terror’ helped mainstream Europe’s far right | Opinions

September 12, 2026

Stranger’s act of kindness leaves Singapore mum touched after he carries injured child to clinic

September 12, 2026

Railway Department issues special notice

September 12, 2026

Sending troops to Ukraine means…: Putin’s warning to Europe

September 12, 2026

Congress’ Manish Tewari as New Delhi gears up to host BRICS Summit

September 12, 2026

TOYO identifies gas chemicals, fertilizers as key areas in Turkmenistan (Exclusive)

September 12, 2026

Israeli demolitions threaten schools and homes in Masafer Yatta | Israel-Palestine conflict News

September 12, 2026

DFA: China’s ‘island-building’ can’t erase PH rights over reefs

September 12, 2026

Jerusalem highlights: September 11-17 | The Jerusalem Post

September 12, 2026

Playing it SAF and fair for our athletes

September 12, 2026

Browns vs. Jaguars Game Day Guide | Week 1

September 12, 2026
Saturday, September 12, 2026
  • About us
  • Advertise with us
  • Submit Articles
  • Privacy Policy
  • Contact us
Asia Today
No Result
View All Result
Subscribe
  • Login
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
No Result
View All Result
Morning News
No Result
View All Result
Home Western Asia United Arab Emirates

WordPress patches critical flaw enabling site takeover — Arabian Post

by Asia Today Team
July 18, 2026
in United Arab Emirates
Reading Time: 3 mins read
21 0
A A
0
WordPress patches critical flaw enabling site takeover — Arabian Post
24
SHARES
303
VIEWS
Share on FacebookShare on Twitter

READ ALSO

VinFast Partners With 13 Electric Vehicle Dealers To Develop 27 New Showrooms Across The Philippines — Arabian Post

Lee rating drops as Hormuz deployment opposition grows — Arabian Post


WordPress has issued emergency safety updates to dam a vital vulnerability that allowed unauthenticated attackers to execute code on web sites working normal installations with out plugins.

The flaw, dubbed “wp2shell” and tracked as CVE-2026-63030, affected WordPress 6.9.0 by 6.9.4 and variations 7.0.0 and seven.0.1. WordPress launched variations 6.9.5 and seven.0.2 on July 17, urging directors to put in the patches instantly.

The vulnerability carried distinctive threat as a result of an attacker didn’t require a legitimate account, administrator privileges or consumer interplay. A specifically ready nameless request might exploit weaknesses within the WordPress REST API and doubtlessly run arbitrary code on the underlying server.

Profitable exploitation might give an intruder management over a web site, its database and saved data. Attackers might alter pages, steal credentials, implant malicious software program, redirect guests or use compromised servers to launch additional assaults.

WordPress activated pressured updates by its automatic-update system due to the severity of the problem. Web sites that help automated background updates ought to obtain the patched launch, though directors have been suggested to confirm the model put in reasonably than assume the method has accomplished efficiently.

The vulnerability arose from confusion within the dealing with of REST API batch routes, mixed with an SQL injection situation that would result in distant code execution. The affected part permits a number of REST API requests to be processed collectively, enhancing effectivity for purposes interacting with WordPress.

Safety researcher Adam Kues, working with Assetnote and Searchlight Cyber, recognized the flaw and reported it privately in order that fixes may very well be ready earlier than technical particulars had been made public. The difficulty was assigned a vital severity score as a result of exploitation was potential over a community with low complexity and with out authentication.

A inventory WordPress set up may very well be weak even when no third-party themes or plugins had been put in. That attribute distinguishes wp2shell from many widespread WordPress compromises, which generally exploit poorly maintained extensions reasonably than the platform’s core software program.

WordPress 6.9 was affected by each the vital remote-code-execution vulnerability and a separate high-severity SQL injection flaw, tracked as CVE-2026-60137. Model 6.9.5 incorporates fixes for each points. WordPress 6.8 was affected solely by the separate SQL injection drawback and has been patched by model 6.8.6.

Variations launched earlier than WordPress 6.8 should not affected by both of the newly disclosed vulnerabilities. Nonetheless, operators utilizing older branches nonetheless face safety dangers arising from unsupported software program and beforehand disclosed flaws. WordPress maintains that solely its latest launch receives full lively help.

The beta model of WordPress 7.1 was additionally affected. Builders and testing groups utilizing that department have been directed to maneuver to WordPress 7.1 Beta 2, which incorporates the required fixes. Manufacturing web sites should not alleged to run beta software program.

The replace modifies three core information related to REST API processing and database queries: class-wp-rest-server. php, class-wp-query. php and rest-api. php. No WordPress packages had been revised as a part of the safety launch.

WordPress is used throughout an unlimited vary of internet sites, from private blogs and small companies to information platforms, on-line outlets and authorities portals. Estimates place its world footprint at lots of of tens of millions of websites, magnifying the potential influence of a core vulnerability that may be exploited with out credentials.

Web site house owners ought to verify that their installations now present WordPress 7.0.2, 6.9.5 or one other unaffected model. Directors working the 6.8 department ought to improve to a minimum of 6.8.6 due to the accompanying SQL injection repair.

Operators unable to replace mechanically can set up the discharge by the Dashboard’s Updates part. Managed internet hosting clients ought to confirm whether or not their supplier has utilized the patch, significantly when replace controls are dealt with centrally.

Safety groups have additionally suggested directors to look at server entry logs, sudden administrator accounts, unfamiliar scheduled duties and adjustments to core information. Unexplained redirects, injected scripts or newly created PHP information could point out compromise.



Source link

Tags: ArabiancriticalEnablingflawpatchesPostsitetakeoverWordPress

Related Posts

United Arab Emirates

VinFast Partners With 13 Electric Vehicle Dealers To Develop 27 New Showrooms Across The Philippines — Arabian Post

September 12, 2026
United Arab Emirates

Lee rating drops as Hormuz deployment opposition grows — Arabian Post

September 11, 2026
United Arab Emirates

Algeria severs diplomatic relations with United Arab Emirates — Arabian Post

September 10, 2026
United Arab Emirates

Apple unveils iPhone Duo as first foldable handset — Arabian Post

September 10, 2026
United Arab Emirates

BJP’s infiltrator politics in Assam on test — Arabian Post

September 9, 2026
United Arab Emirates

AMAP Platform Showcases Spatial Intelligence at Qwen Conference Thailand 2026 — Arabian Post

September 8, 2026
Asia Today

Copyright © 2022 Asia Today.

Navigate Site

  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • DMCA
  • Terms and Conditions
  • Contact us

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Homepages
  • World
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Sri Lanka
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • Opinion
  • Politics
  • Business
  • Entertainment
  • Fashion
  • Food
  • Health
  • Lifestyle
  • Science
  • Tech
  • Travel
  • Sports
  • About us
  • Advertise with us
  • Privacy Policy
  • Contact us
  • Support AsiaToday

Copyright © 2022 Asia Today.