A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a loggedin administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE202693485 and called "Comment2Shell," on September 17 in version 7.1.1 and told site owners to update right away. There is.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity