Like any CMS, Comedian’s with various vices or humans with a disposition for distrust,
The more elements in play, the more potential security issues/attack vectors, more moving parts.We can’t fix everything, all the time, but we get pretty close. If you can stop your kids naturally selecting themselves before their 30’s, anything else should be a cakewalk.
WordPress Core
https://thehackernews.com/2023/05/new-vulnerability-in-popular-wordpress.html
https://ithemes.com/blog/wordpress-vulnerability-report-may-31-2023/
Users of Advanced Custom Fields plugin for WordPress are being urged to update version 6.1.6 following the discovery of a security flaw.
The issue, assigned the identifier CVE-2023-30777, relates to a case of reflected cross-site scripting (XSS) that could be abused to inject arbitrary executable scripts into otherwise benign websites.