Monthly Archives: June 2023

WP Vulnerabilities, patching

Like any CMS, Comedian’s with various vices or humans with a disposition for distrust,

The more elements in play, the more potential security issues/attack vectors, more moving parts.We can’t fix everything, all the time, but we get pretty close. If you can stop your kids naturally selecting themselves before their 30’s, anything else should be a cakewalk.

WordPress Core

VulnerabilityUnauth. Shortcode Execution
Patched in Version6.2.2
Medium Severity
The vulnerability has been patched, so you should update to version 6.2.2.

https://thehackernews.com/2023/05/new-vulnerability-in-popular-wordpress.html

 

 

https://ithemes.com/blog/wordpress-vulnerability-report-may-31-2023/

Users of Advanced Custom Fields plugin for WordPress are being urged to update version 6.1.6 following the discovery of a security flaw.

The issue, assigned the identifier CVE-2023-30777, relates to a case of reflected cross-site scripting (XSS) that could be abused to inject arbitrary executable scripts into otherwise benign websites.