News

The recently patched REST API Endpoint vulnerability in WordPress could be leveraged to pull off stored cross-site scripting attacks.
Now we get a better sense of Krogsgard's excitement over WordPress' new direction and the range of projects he predicts WordPress will be used to support. "The REST API makes WordPress more ...
Attackers have found a way to escalate the benign WordPress REST API flaw and use it to gain full access to a victim's server by installing a hidden backdoor.
The REST API allows plugins, themes and other applications to manipulate WordPress content and create interactive functionalities. This technology extends what the WordPress core can do.
A WordPress core maintainer said the company delayed disclosing the vulnerability, technically an unauthenticated privilege escalation vulnerability that existed in a REST API endpoint, to ...