WordPress 7.1.2 Fixes a Critical Flaw Attackers Are Already Using
A core WordPress bug let attackers load PHP files without logging in. Attacks began within hours of the fix, and CISA now lists it as exploited.
Web hosting, domains, email and websites for local business
Topic hub
Security news for people who run a business website. What broke, who it hits, and what to do.
3 stories, 3 guides, 19 key terms
A core WordPress bug let attackers load PHP files without logging in. Attacks began within hours of the fix, and CISA now lists it as exploited.
Wordfence says it blocked more than 440,000 attempts to abuse file upload bugs in Super Forms and Elementor Pro. Both have fixes.
A flaw in All-in-One WP Migration and Backup could be set off when an owner restores a backup. Version 7.110 fixes it.
From T3CHS, not the news desk
We keep site software patched and backed up for small business sites.
See Hosting