news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans WordPress (20 juillet 2026)

High
Summary

Multiple vulnerabilities have been discovered in WordPress, allowing attackers to execute arbitrary code remotely and bypass security policies. The CERT-FR has a public proof of concept demonstrating the impact. Users of vulnerable WordPress versions need to apply the latest security updates immediately.

Multiple security vulnerabilities have been identified within the WordPress platform. These vulnerabilities enable attackers to execute arbitrary code remotely and circumvent WordPress’s security policies. The CERT-FR has released a proof of concept to demonstrate the exploitability of these flaws. Specifically, versions 6.8.x prior to 6.8.6, 6.9.x prior to 6.9.5, 7.1.x prior to 7.1 beta2, and all versions prior to 7.0.2 are affected. The CERT-FR’s investigation indicates that combining these vulnerabilities allows an unauthenticated attacker to achieve remote code execution. Users are strongly advised to update their WordPress installations to the latest secure version as soon as possible.

Read the full article at CERT-FR