WordPress 7.1.3 fixes seven security flaws, including XSS and SQL injection bugs
The WordPress project released version 7.1.3 on October 6 with seven security fixes and four bug fixes, urging site owners to update immediately.
Cybersecurity news about “WordPress”.
The WordPress project released version 7.1.3 on October 6 with seven security fixes and four bug fixes, urging site owners to update immediately.
Patchstack says a single campaign is abusing stored XSS bugs in Ninja Forms and WPC Product Bundles to create admin accounts, a magic login link and a file manager backdoor.
Sucuri researchers detailed SC, a WordPress backdoor that keeps copies in at least eight places across files, the database and shared memory, each able to rebuild the others.