Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

Update WordPress now to fix this significant security flaw

WordPress.

WordPress has released a new version - 6.4.2, that fixes a remote code execution vulnerability. Used in pair with another flaw, hackers could run arbitrary PHP code on a WordPress website, and as almost half of the internet is thought to run on WordPress, the attack surface is quite wide.

As per the website builder security team, version 6.4 was vulnerable to a Property Oriented Programming (POP) chain flaw that could be used for arbitrary PHP code execution, albeit under specific circumstances. Those circumstances require the target website to carry a PHP object injection flaw, which could be introduced with a vulnerable plug-in, or an add-on. Together, the flaws become critical in severity.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.