A High-Severity Patch for Five Million WordPress Sites Was Labeled as a Text Fix
Two unauthenticated WordPress plugin vulnerabilities became public in recent days: an SQL injection in All-in-One WP Migration and Backup, installed on five million-plus sites per the WordPress.org directory, and an arbitrary file upload in Gravity Forms, a commercial form plugin. Both fixes shipped on August 20, the same day. What makes the pair worth a closer look is not the bugs themselves but…
评论
?
参与讨论