WordPress upgraded to 4.3.1, patching a pair of vulnerabilities in the core engine, including a cross-site scripting issue enabled by a vulnerability in shortcodes. WordPress core engine security ...
An advisory has been issued about a high-severity WordPress vulnerability that makes it possible for attackers to inject arbitrary shortcodes into sites using the WordPress Popular Posts plugin.
The WordPress security team has pushed an emergency release with the aim of fixing three major security flaws, more precisely two XSS (cross-site scripting) vulnerabilities and a potential privilege ...