Skip to main content
Back to Newswire
Security

Five critical WordPress flaws expose sites to takeover or code execution

Five critical WordPress flaws expose sites to takeover or code execution Image: Primary
Multiple critical flaws disclosed in WordPress plugins and themes could allow unauthenticated attackers to take over administrator accounts or execute code on affected servers. The affected products include WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP. The source lists CVSS scores of 9.8 for four issues and 10.0 for the GiveWP vulnerability, with attack conditions varying by product configuration. The disclosures identify affected versions but do not state whether fixes are available or whether the flaws are being exploited.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire