CISOOnline

Patch now: WordPress REST API bug allows remote code execution

In a technical analysis published by Hadrian, researchers reconstructed the root cause from WordPress’ security patch released on July 17. The vulnerability, they said, resides in the core REST API batch endpoint “batch/v1,” where an indexing mismatch during request validation can cause request objects and their associated permission checks to become misaligned.

As a result, a crafted batch request can be processed under the wrong authorization context, ultimately allowing remote code execution.

“An attacker who reaches the bug gains unauthenticated code execution on the web server,” the researchers said. “In practice, that means full control of the site and its content, access to the database and whatever credentials or personal data it holds, and a way into the surrounding hosting environment.”



Source link