Follow the latest coverage, related explainers and connected technology stories.
Researchers disclosed details of a CSRF vulnerability in the WordPress core that, without requiring an attacker account, allows a site to be forced to install a theme and execute PHP code, provided that a logged-in administrator visits a specially crafted link. WordPress addressed the issue in version 7.1.1, while the proof-of-concept exploit has become publicly available.