🔴 Critical  |  Source: The Register — Security


A critical vulnerability in WordPress is being actively exploited in the wild, with attackers leveraging it to cause a range of malicious outcomes including site takeovers and malware injection. Dozens of proof-of-concept exploits have been published publicly, significantly lowering the bar for less skilled attackers. The combination of active exploitation and widespread PoC availability makes this an urgent patching priority for any organisation running WordPress.

Security Architect’s Take: Audit all WordPress deployments across your cloud estate immediately and apply the relevant patch or mitigation — prioritise internet-facing instances and those handling sensitive data. Consider deploying a Web Application Firewall (WAF) rule to virtual-patch the vulnerability whilst remediation is scheduled, and review whether your vulnerability management pipeline has visibility into CMS-layer risks, not just OS and container layers.

Original advisory: Attackers pummel critical WordPress vuln to create all sorts of mischief