• Latest
WordPress patches critical flaw enabling site takeover — Arabian Post

WordPress patches critical flaw enabling site takeover — Arabian Post

July 18, 2026
UP Cabinet Approves ₹20 Crore for UPKAS, Clears Scooty Scheme and Major Infrastructure Projects

UP Cabinet Approves ₹20 Crore for UPKAS, Clears Scooty Scheme and Major Infrastructure Projects

July 21, 2026
CAA raids 112 shops & eateries near bus terminals – Sri Lanka Mirror – Right to Know. Power to Change

CAA raids 112 shops & eateries near bus terminals – Sri Lanka Mirror – Right to Know. Power to Change

July 21, 2026
Toppled tree causes power outage in 3 Lanao del Norte towns

Toppled tree causes power outage in 3 Lanao del Norte towns

July 21, 2026
Cool down this National Ice Cream Month with top machines starting at  – Tom's Guide

Cool down this National Ice Cream Month with top machines starting at $54 – Tom's Guide

July 21, 2026
le coût caché des banques

le coût caché des banques

July 21, 2026
(LEAD) Arrest warrant denied for woman accused of blockading vote counting center

(LEAD) Arrest warrant denied for woman accused of blockading vote counting center

July 21, 2026
ICC World Cup 2027 Qualification Race Explained: Who's In & Who Faces Elimination?

ICC World Cup 2027 Qualification Race Explained: Who's In & Who Faces Elimination?

July 21, 2026
Captain Rahul Bali Delivers Inspiring Keynote at International Wedding and Tourism Conclave 2026

Captain Rahul Bali Delivers Inspiring Keynote at International Wedding and Tourism Conclave 2026

July 21, 2026
Tokyo-area condo prices hit record high in first half of 2026

Tokyo-area condo prices hit record high in first half of 2026

July 21, 2026
LHDN Expands MyTax e-Assessment Appeal System

LHDN Expands MyTax e-Assessment Appeal System

July 21, 2026
Tilak Varma fires back, responds to criticism over low strike-rate in T20Is: ‘When you are the vice-captain…’

Tilak Varma fires back, responds to criticism over low strike-rate in T20Is: ‘When you are the vice-captain…’

July 21, 2026
Kuwait summons Iran envoy over attack on ship

Kuwait summons Iran envoy over attack on ship

July 21, 2026
Tuesday, July 21, 2026
  • About us
  • Advertise with us
  • Submit Articles
  • Privacy Policy
  • Contact us
Asia Today
No Result
View All Result
Subscribe
  • Login
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
No Result
View All Result
Morning News
No Result
View All Result
Home Western Asia United Arab Emirates

WordPress patches critical flaw enabling site takeover — Arabian Post

by Asia Today Team
July 18, 2026
in United Arab Emirates
Reading Time: 3 mins read
21 0
A A
0
WordPress patches critical flaw enabling site takeover — Arabian Post
24
SHARES
303
VIEWS
Share on FacebookShare on Twitter

READ ALSO

Discover Malaysia at Each Individual’s Pace, with Meaningful Moments Throughout the Trip — Arabian Post

UAE PASS promoted to world government’s password — Arabian Post


WordPress has issued emergency safety updates to dam a vital vulnerability that allowed unauthenticated attackers to execute code on web sites working normal installations with out plugins.

The flaw, dubbed “wp2shell” and tracked as CVE-2026-63030, affected WordPress 6.9.0 by 6.9.4 and variations 7.0.0 and seven.0.1. WordPress launched variations 6.9.5 and seven.0.2 on July 17, urging directors to put in the patches instantly.

The vulnerability carried distinctive threat as a result of an attacker didn’t require a legitimate account, administrator privileges or consumer interplay. A specifically ready nameless request might exploit weaknesses within the WordPress REST API and doubtlessly run arbitrary code on the underlying server.

Profitable exploitation might give an intruder management over a web site, its database and saved data. Attackers might alter pages, steal credentials, implant malicious software program, redirect guests or use compromised servers to launch additional assaults.

WordPress activated pressured updates by its automatic-update system due to the severity of the problem. Web sites that help automated background updates ought to obtain the patched launch, though directors have been suggested to confirm the model put in reasonably than assume the method has accomplished efficiently.

The vulnerability arose from confusion within the dealing with of REST API batch routes, mixed with an SQL injection situation that would result in distant code execution. The affected part permits a number of REST API requests to be processed collectively, enhancing effectivity for purposes interacting with WordPress.

Safety researcher Adam Kues, working with Assetnote and Searchlight Cyber, recognized the flaw and reported it privately in order that fixes may very well be ready earlier than technical particulars had been made public. The difficulty was assigned a vital severity score as a result of exploitation was potential over a community with low complexity and with out authentication.

A inventory WordPress set up may very well be weak even when no third-party themes or plugins had been put in. That attribute distinguishes wp2shell from many widespread WordPress compromises, which generally exploit poorly maintained extensions reasonably than the platform’s core software program.

WordPress 6.9 was affected by each the vital remote-code-execution vulnerability and a separate high-severity SQL injection flaw, tracked as CVE-2026-60137. Model 6.9.5 incorporates fixes for each points. WordPress 6.8 was affected solely by the separate SQL injection drawback and has been patched by model 6.8.6.

Variations launched earlier than WordPress 6.8 should not affected by both of the newly disclosed vulnerabilities. Nonetheless, operators utilizing older branches nonetheless face safety dangers arising from unsupported software program and beforehand disclosed flaws. WordPress maintains that solely its latest launch receives full lively help.

The beta model of WordPress 7.1 was additionally affected. Builders and testing groups utilizing that department have been directed to maneuver to WordPress 7.1 Beta 2, which incorporates the required fixes. Manufacturing web sites should not alleged to run beta software program.

The replace modifies three core information related to REST API processing and database queries: class-wp-rest-server. php, class-wp-query. php and rest-api. php. No WordPress packages had been revised as a part of the safety launch.

WordPress is used throughout an unlimited vary of internet sites, from private blogs and small companies to information platforms, on-line outlets and authorities portals. Estimates place its world footprint at lots of of tens of millions of websites, magnifying the potential influence of a core vulnerability that may be exploited with out credentials.

Web site house owners ought to verify that their installations now present WordPress 7.0.2, 6.9.5 or one other unaffected model. Directors working the 6.8 department ought to improve to a minimum of 6.8.6 due to the accompanying SQL injection repair.

Operators unable to replace mechanically can set up the discharge by the Dashboard’s Updates part. Managed internet hosting clients ought to confirm whether or not their supplier has utilized the patch, significantly when replace controls are dealt with centrally.

Safety groups have additionally suggested directors to look at server entry logs, sudden administrator accounts, unfamiliar scheduled duties and adjustments to core information. Unexplained redirects, injected scripts or newly created PHP information could point out compromise.



Source link

Tags: ArabiancriticalEnablingflawpatchesPostsitetakeoverWordPress

Related Posts

Discover Malaysia at Each Individual’s Pace, with Meaningful Moments Throughout the Trip — Arabian Post
United Arab Emirates

Discover Malaysia at Each Individual’s Pace, with Meaningful Moments Throughout the Trip — Arabian Post

July 21, 2026
UAE PASS promoted to world government’s password — Arabian Post
United Arab Emirates

UAE PASS promoted to world government’s password — Arabian Post

July 20, 2026
VinFast builds Philippine electric motorcycle logistics hub — Arabian Post
United Arab Emirates

VinFast builds Philippine electric motorcycle logistics hub — Arabian Post

July 19, 2026
VinFast partners with Bespoke Logistics to strengthen electric motorcycle logistics capabilities in the Philippines — Arabian Post
United Arab Emirates

VinFast partners with Bespoke Logistics to strengthen electric motorcycle logistics capabilities in the Philippines — Arabian Post

July 20, 2026
Spanish Espadrille Maker Turns 80 as Gulf Demand Reshapes Its Retail Map — Arabian Post
United Arab Emirates

Spanish Espadrille Maker Turns 80 as Gulf Demand Reshapes Its Retail Map — Arabian Post

July 18, 2026
Dubai rejects report of Downtown explosions — Arabian Post
United Arab Emirates

Dubai rejects report of Downtown explosions — Arabian Post

July 17, 2026
Asia Today

Copyright © 2022 Asia Today.

Navigate Site

  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • DMCA
  • Terms and Conditions
  • Contact us

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Homepages
  • World
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Sri Lanka
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • Opinion
  • Politics
  • Business
  • Entertainment
  • Fashion
  • Food
  • Health
  • Lifestyle
  • Science
  • Tech
  • Travel
  • Sports
  • About us
  • Advertise with us
  • Privacy Policy
  • Contact us
  • Support AsiaToday

Copyright © 2022 Asia Today.