The Register Home Page

back to article Attackers pummel critical WordPress vuln to create all sorts of mischief

If you use WordPress, patch now. Just hours after fixes came out, attackers have begun exploiting two bugs that, when chained together, allow pre-authentication remote code execution (RCE). And security researchers tell us there’s a very good chance the miscreants had an AI assist. “Once the vulnerabilities were publicly …

  1. IGotOut Silver badge

    Maybe a bit OTT

    "Any orgs that waited until Monday to patch are likely already compromised, Knott warned."

    Well running the test against my instance.

    "Not vulnerable

    The batch API is blocked (likely by a WAF or security plugin), so it cannot be exploited. Keep WordPress up to date regardless."

    So it seems that the "already compromised" is hyperbole.

    1. AMBxx Silver badge
      WTF?

      Re: Maybe a bit OTT

      Not sure why you've been downvoted (comments would be helpful).

      I'm in a similar position,I can only connect to the admin and other bits via VPN (tailscale). Everything else is blocked at Cloudflare with a bunch of security rules.

      1. Anonymous Coward
        Anonymous Coward

        Re: Maybe a bit OTT

        Because unless its an on-premise WAF and your firewall blocks connections that don't traverse your WAF, you're still vulnerable to direct connections.

        The other thing to think about is horizontal escape from a co-hosted instance that isn't patched.

    2. meander

      Re: Maybe a bit OTT

      "So it seems that the "already compromised" is hyperbole."

      Well, I see I've been auto updated to v 7.02, but found 2 unknown admin users and an auto update to admin plugin.

      Despite the "hyperbole", I quickly removed them. Thank you TheRegister for this alert.

  2. DrewPH Silver badge

    Versions...

    "WordPress 6.9 is affected by both vulnerabilities, and version 6.9.5 contains fixes for both, while WordPress 6.8 is only affected by the SQL injection flaw, and version 6.8.6 fixes it.

    Additionally, WordPress 7.1 Beta 1 is also vulnerable. Version 7.1 Beta 2 fixes both CVEs.

    Versions of WordPress prior to 6.8 are not affected."

    Never mind about old versions or betas, what about 7.0.x which is the current version?

    1. Kurgan Silver badge

      Re: Versions...

      7.0.2 is the fixed one. 7.x is vulnerabile.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon