WordPress가 사이트 공격에 대한 취약점을 수정했습니다.
WordPress는 공격자가 계정 없이 외부 PHP 파일을 로드할 수 있는 취약점을 수정하였습니다. 이 결함은 일부 서버에서 악성 코드를 실행할 수 있는 가능성을 불러일으킵니다. 해당 수정사항은 9월 22일에 WordPress 7.1.2로 배포되었으며, 여전히 지원되는 모든 버전에 적용되었습니다.
WordPress has patched a critical vulnerability that allows code execution by attackers.
WordPress has addressed a serious flaw that permits attackers to load PHP files from outside theme folders without an account. On certain servers, this flaw could allow them to execute their own code. The fix was released on September 22 as part of WordPress 7.1.2, covering all supported branches back to version 4.7.