Skip to content
The Cyber Security Place

Software

WordPress admins, take note: RCE and password reset vulnerabilities revealed - Help Net Security

Reported by helpnetsecurity.com

Independent security researcher Dawid Golunski has released a proof-of-concept exploit code for an unauthenticated remote code execution vulnerability in WordPress 4.6 (CVE-2016-10033), and information about an unauthorized password reset zero-day vulnerability (CVE-2017-8295) in the latest version of the popular CMS.

Read the full article at helpnetsecurity.com