Vulnerability Bulletins

WordPress Core Vulnerability let authors delete any file, updated video

   
Affected software Wordpress
 
https://secupress.me/blog/wordpress-core-vulnerability-496/Today, Karim El Ouerghemmi discloses a critical WordPress vulnerability allowing any author, editor, administrator to delete any file of the installation, in any folder, without any tool. In less than 1 minute, a website can be gone. The flaw is known from WordPress Core Security Team since about 7 months but still no patch has been […]

More info:

https://secupress.me/blog/wordpress-core-vulnerability-496/