WordPress Patch Fixes Serious Remote Code Execution Flaw
WordPress has released version 7.0.4 to fix a remote code execution vulnerability that could allow attackers with Author-level permissions or higher to compromise a website. The flaw is triggered through malicious Postscript files uploaded to the site, potentially giving an attacker the ability to run arbitrary code and take control of the affected system.
While this vulnerability requires an attacker to already have some level of authenticated access, this is not as reassuring as it sounds. Many small businesses use WordPress with multiple contributors, guest authors, or contractors who may have Author-level accounts, and compromised credentials for these accounts are a common attack vector. If exploited, this flaw could let an attacker escalate their access and cause significant damage to a business's website or the data it holds.
Businesses running WordPress should treat this as a priority update, especially those with several user accounts of Author level or above. Delaying patching increases the window in which a stolen or weak password could be leveraged into full site compromise.