WordPress Releases Critical Security Update 7.0.2 to Patch Severe SQL Injection and REST API FlawsWordPress has officially released security update version 7.0.2, addressing two significant security vulnerabilities, including a Critical-severity SQL Injection (SQLi) flaw and a High-severity REST API vulnerability. Core developers are strongly advising all system administrators to update their installations immediately to prevent potential remote exploitation.
For websites configured with automatic core updates, WordPress.org has already deployed background security patches automatically.
The vulnerabilities also impact several prior release branches of the Content Management System (CMS). Security backports have been issued across affected versions:
WordPress 6.9: Update immediately to 6.9.5.
WordPress 6.8: Update immediately to 6.8.6.
WordPress 7.1 Beta: Update immediately to Beta 2.
Note: Legacy installations running version 6.8 or older are confirmed to be unaffected by these specific vulnerabilities.
In response to the disclosure, major edge security provider Cloudflare confirmed that it has updated its Web Application Firewall (WAF) rule sets. Automated mitigation rules protecting against exploit attempts targeting both the SQL Injection and REST API vulnerabilities have been deployed across all Cloudflare service tiers, including free accounts.
The severity of SQL Injection (SQLi) vulnerabilities allows attackers to directly inject malicious commands into a website's database, potentially leading to credential exfiltration or administrator takeover. Combined with REST API vulnerabilities, the primary communication channel for modern websites, this further facilitates automated exploit bots globally.
The operation of WordPress Security Auto-Updates for millions of websites worldwide: Enabling Minor Automatic Updates is the first line of defense against hacking. When vulnerability information is publicly disclosed, hackers often reverse engineer the patches to find ways to exploit unupdated websites (zero-day and N-day exploits).
The role of Edge Protection: Cloudflare's updating of WAF rules for users at all levels reflects this concept. "Defense-in-Depth" (multi-layered protection): Even if web administrators don't immediately update the backend code, having a WAF (Network Edge) filtering abnormal traffic buys time for the IT team to securely test and update the system.
Source: TechCrunch
WordPress Releases Critical Security Update 7.0.2 to Patch Severe SQL Injection and REST API FlawsWordPress has officially released security update version 7.0.2, addressing two significant security vulnerabilities, including a Critical-severity SQL Injection (SQLi) flaw and a High-severity REST API vulnerability. Core developers are strongly advising all system administrators to update their installations immediately to prevent potential remote exploitation.
For websites configured with automatic core updates, WordPress.org has already deployed background security patches automatically.
The vulnerabilities also impact several prior release branches of the Content Management System (CMS). Security backports have been issued across affected versions:
WordPress 6.9: Update immediately to 6.9.5.
WordPress 6.8: Update immediately to 6.8.6.
WordPress 7.1 Beta: Update immediately to Beta 2.
Note: Legacy installations running version 6.8 or older are confirmed to be unaffected by these specific vulnerabilities.
In response to the disclosure, major edge security provider Cloudflare confirmed that it has updated its Web Application Firewall (WAF) rule sets. Automated mitigation rules protecting against exploit attempts targeting both the SQL Injection and REST API vulnerabilities have been deployed across all Cloudflare service tiers, including free accounts.
The severity of SQL Injection (SQLi) vulnerabilities allows attackers to directly inject malicious commands into a website's database, potentially leading to credential exfiltration or administrator takeover. Combined with REST API vulnerabilities, the primary communication channel for modern websites, this further facilitates automated exploit bots globally.
The operation of WordPress Security Auto-Updates for millions of websites worldwide: Enabling Minor Automatic Updates is the first line of defense against hacking. When vulnerability information is publicly disclosed, hackers often reverse engineer the patches to find ways to exploit unupdated websites (zero-day and N-day exploits).
The role of Edge Protection: Cloudflare's updating of WAF rules for users at all levels reflects this concept. "Defense-in-Depth" (multi-layered protection): Even if web administrators don't immediately update the backend code, having a WAF (Network Edge) filtering abnormal traffic buys time for the IT team to securely test and update the system.
Source: TechCrunch
Comments
Post a Comment