◈ Cii.中国 · 天地一体信息中心 九霄观澜 · 宇宙观察 · RSS

WordPress针对可能在某些服务器上启用代码执行的关键缺陷发布修补程序

暗流情报2026-09-22 · 来源:开源情报·The Hacker News
WordPress针对可能在某些服务器上启用代码执行的关键缺陷发布修补程序

WordPress已修复其核心软件中的一个严重漏洞,该漏洞允许没有帐户的攻击者让网站从其主题文件夹外部加载PHP文件。在某些服务器上,这可以更进一步,允许

原文标题:WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

信源:The Hacker News | 阅读原文

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on Sep

—— 开源情报自动采集 · 海