Key takeaways WordPress shipped an emergency security release, 7.0.3, on 6 August. The headline flaw is a scripting vulnerability on the login screen that needs no account to trigger. Researchers demonstrated a chain from that flaw to code execution on the server, but the chain needs a logged-in administrator to interact with an attacker-controlled page. […]
Read More