Attackers pummel critical WordPress vuln to create all sorts of mischief

← Back to the feed

Attackers pummel critical WordPress vuln to create all sorts of mischief

The Register · 12 hours ago

WordPress administrators faced urgent security demands after disclosure of two chained vulnerabilities—a REST API routing confusion bug and SQL injection flaw—that collectively bypass authentication to enable remote code execution. Security patches released Friday for versions 6.9, 6.8, and 7.1 Beta were quickly overtaken by active exploitation; researchers indicated artificial intelligence likely accelerated the weaponisation process.

Within 48 hours, attackers deployed working exploits targeting organisations across sectors and sizes. WordPress responded by mandating forced automatic updates for vulnerable installations, whilst researchers released diagnostic utilities. By Sunday, verified PoC exploits numbered in the dozens, and successful attacks harvesting credentials and executing arbitrary code were well underway.

  • Two interconnected WordPress flaws enabling unauthenticated remote code execution were exploited within hours of patches being released, affecting versions 6.8, 6.9, and 7.1 Beta 1
  • Attackers rapidly weaponised the vulnerabilities using public exploit code and potentially AI assistance; dozens of proof-of-concept exploits circulated by Sunday across all organisation sizes

Americas World

Read the full article at the source →