• Latest
WordPress patches critical flaw enabling site takeover — Arabian Post

WordPress patches critical flaw enabling site takeover — Arabian Post

July 18, 2026

Dino Morea Leaves Mumbai Police Station After Hours Of Questioning In Mithi River Scam

October 2, 2026

How six villages turn viral fame into shared prosperity — Arabian Post

October 2, 2026

Ethiopia, Eritrea break ties: Does the conflict risk becoming regional war? | Conflict News

October 2, 2026

Sri Lanka begins jet fuel pipeline and new storage tank projects

October 2, 2026

What legal options does Centre have to intervene?

October 2, 2026

Escalator maintenance company slapped with S$15K fine after elderly man & woman fell in Hougang

October 2, 2026

Bilawal hails govt-opposition talks, hopes for unconditional end to long march

October 3, 2026

Üstel says Greek Cypriot military build-up undermines peace rhetoric

October 2, 2026

Rep. Brian Poe seeks P100-M funding for ube industry

October 2, 2026

PM Modi Speaks To Flydubai Pilot Smit Machchhar After Alleged Mid-Air Attack, Says ‘Country Is Praying For You’

October 2, 2026

Doha & Abu Dhabi Airports Named World’s Most Beautiful

October 2, 2026

National programme launched to ensure “Poison-Free Fruits for Children” – Sri Lanka Mirror – Right to Know. Power to Change

October 2, 2026
Saturday, October 3, 2026
  • About us
  • Advertise with us
  • Submit Articles
  • Privacy Policy
  • Contact us
Asia Today
No Result
View All Result
Subscribe
  • Login
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Sri Lanka
  • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • More News
    • Opinion
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Food
    • Health
    • Lifestyle
    • Science
    • Tech
    • Sports
No Result
View All Result
Morning News
No Result
View All Result
Home Western Asia United Arab Emirates

WordPress patches critical flaw enabling site takeover — Arabian Post

by Asia Today Team
July 18, 2026
in United Arab Emirates
Reading Time: 3 mins read
21 0
A A
0
WordPress patches critical flaw enabling site takeover — Arabian Post
24
SHARES
303
VIEWS
Share on FacebookShare on Twitter

READ ALSO

How six villages turn viral fame into shared prosperity — Arabian Post

Ghana, Philippines expand trade ties ahead of embassy — Arabian Post


WordPress has issued emergency safety updates to dam a vital vulnerability that allowed unauthenticated attackers to execute code on web sites working normal installations with out plugins.

The flaw, dubbed “wp2shell” and tracked as CVE-2026-63030, affected WordPress 6.9.0 by 6.9.4 and variations 7.0.0 and seven.0.1. WordPress launched variations 6.9.5 and seven.0.2 on July 17, urging directors to put in the patches instantly.

The vulnerability carried distinctive threat as a result of an attacker didn’t require a legitimate account, administrator privileges or consumer interplay. A specifically ready nameless request might exploit weaknesses within the WordPress REST API and doubtlessly run arbitrary code on the underlying server.

Profitable exploitation might give an intruder management over a web site, its database and saved data. Attackers might alter pages, steal credentials, implant malicious software program, redirect guests or use compromised servers to launch additional assaults.

WordPress activated pressured updates by its automatic-update system due to the severity of the problem. Web sites that help automated background updates ought to obtain the patched launch, though directors have been suggested to confirm the model put in reasonably than assume the method has accomplished efficiently.

The vulnerability arose from confusion within the dealing with of REST API batch routes, mixed with an SQL injection situation that would result in distant code execution. The affected part permits a number of REST API requests to be processed collectively, enhancing effectivity for purposes interacting with WordPress.

Safety researcher Adam Kues, working with Assetnote and Searchlight Cyber, recognized the flaw and reported it privately in order that fixes may very well be ready earlier than technical particulars had been made public. The difficulty was assigned a vital severity score as a result of exploitation was potential over a community with low complexity and with out authentication.

A inventory WordPress set up may very well be weak even when no third-party themes or plugins had been put in. That attribute distinguishes wp2shell from many widespread WordPress compromises, which generally exploit poorly maintained extensions reasonably than the platform’s core software program.

WordPress 6.9 was affected by each the vital remote-code-execution vulnerability and a separate high-severity SQL injection flaw, tracked as CVE-2026-60137. Model 6.9.5 incorporates fixes for each points. WordPress 6.8 was affected solely by the separate SQL injection drawback and has been patched by model 6.8.6.

Variations launched earlier than WordPress 6.8 should not affected by both of the newly disclosed vulnerabilities. Nonetheless, operators utilizing older branches nonetheless face safety dangers arising from unsupported software program and beforehand disclosed flaws. WordPress maintains that solely its latest launch receives full lively help.

The beta model of WordPress 7.1 was additionally affected. Builders and testing groups utilizing that department have been directed to maneuver to WordPress 7.1 Beta 2, which incorporates the required fixes. Manufacturing web sites should not alleged to run beta software program.

The replace modifies three core information related to REST API processing and database queries: class-wp-rest-server. php, class-wp-query. php and rest-api. php. No WordPress packages had been revised as a part of the safety launch.

WordPress is used throughout an unlimited vary of internet sites, from private blogs and small companies to information platforms, on-line outlets and authorities portals. Estimates place its world footprint at lots of of tens of millions of websites, magnifying the potential influence of a core vulnerability that may be exploited with out credentials.

Web site house owners ought to verify that their installations now present WordPress 7.0.2, 6.9.5 or one other unaffected model. Directors working the 6.8 department ought to improve to a minimum of 6.8.6 due to the accompanying SQL injection repair.

Operators unable to replace mechanically can set up the discharge by the Dashboard’s Updates part. Managed internet hosting clients ought to confirm whether or not their supplier has utilized the patch, significantly when replace controls are dealt with centrally.

Safety groups have additionally suggested directors to look at server entry logs, sudden administrator accounts, unfamiliar scheduled duties and adjustments to core information. Unexplained redirects, injected scripts or newly created PHP information could point out compromise.



Source link

Tags: ArabiancriticalEnablingflawpatchesPostsitetakeoverWordPress

Related Posts

United Arab Emirates

How six villages turn viral fame into shared prosperity — Arabian Post

October 2, 2026
United Arab Emirates

Ghana, Philippines expand trade ties ahead of embassy — Arabian Post

October 2, 2026
United Arab Emirates

Flydubai halts Israel flights during FZ1073 investigation — Arabian Post

October 1, 2026
United Arab Emirates

Lee Kum Kee Receives Packaging Reduction Charter Gold Award — Arabian Post

September 30, 2026
United Arab Emirates

OpenAI withdraws GPT-6.1 Astra after safety tests — Arabian Post

September 30, 2026
United Arab Emirates

China Securities adds Dubai base for Middle East — Arabian Post

September 29, 2026
Asia Today

Copyright © 2022 Asia Today.

Navigate Site

  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • DMCA
  • Terms and Conditions
  • Contact us

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Homepages
  • World
  • Eastern Asia
    • China
    • Japan
    • Mongolia
    • North Korea
    • South Korea
  • South-eastern Asia
    • Brunei
    • Cambodia
    • Indonesia
    • Laos
    • Malaysia
    • Myanmar
    • Philippines
    • Singapore
    • Thailand
    • Timor Leste
    • Vietnam
  • Southern Asia
    • Afghanistan
    • Sri Lanka
    • Bangladesh
    • Bhutan
    • India
    • Iran
    • Maldives
    • Nepal
    • Pakistan
    • Central Asia
    • Kazakhstan
    • Kyrgyzstan
    • Tajikistan
    • Turkmenistan
    • Uzbekistan
  • Western Asia
    • Armenia
    • Azerbaijan
    • Bahrain
    • Cyprus
    • Georgia
    • Iraq
    • Israel
    • Jordan
    • Kuwait
    • Lebanon
    • Oman
    • Qatar
    • Saudi Arabia
    • State of Palestine
    • Syria
    • Turkey
    • United Arab Emirates
    • Yemen
  • Opinion
  • Politics
  • Business
  • Entertainment
  • Fashion
  • Food
  • Health
  • Lifestyle
  • Science
  • Tech
  • Travel
  • Sports
  • About us
  • Advertise with us
  • Privacy Policy
  • Contact us
  • Support AsiaToday

Copyright © 2022 Asia Today.