• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

WordPress Safety Launch 7.0.3 Fixes Excessive Severity XSS Vulnerability

Admin by Admin
August 7, 2026
Home SEO
Share on FacebookShare on Twitter


WordPress introduced a safety launch 7.0.3 to repair twelve vulnerabilities, three of which seem like pretty severe, with one vulnerability rated 8.9/10 Excessive.

Twelve WordPress Vulnerabilities In Core

Prior to now it’s been comparatively uncommon for vulnerabilities to be found in WordPress however just lately there have been an uncommon cluster of vulnerability discoveries, aided by AI.

There are twelve vulnerabilities and the official WordPress announcement solely offers the naked minimal description of what they’re and nil severity data, making it laborious for the typical WordPress customers to grasp the urgency and significance of the patches.

These are the twelve vulnerabilities:

  1. A Contributor+ saved cross-site scripting (XSS) problem within the Put up Date block
  2. A Contributor+ saved cross-site scripting (XSS) problem within the Put up Content material block
  3. An data disclosure problem within the Newest Feedback block exposing feedback on password-protected posts
  4. A bypass of the e-mail handle affirmation circulate
  5. An Writer+ CSS injection problem by way of a bypass of the protected CSS attribute filter
  6. A Contributor+ saved cross-site scripting (XSS) problem in posts by way of the emoji settings ingredient
  7. A privilege escalation problem on multisite networks with consumer registration enabled, permitting a consumer to create a brand new website
  8. A server-side request forgery (SSRF) problem in URL validation permitting requests to link-local ranges
  9. A pre-auth mirrored cross-site scripting (XSS) problem on the login display with potential to result in PHP code execution
  10. A disclosure of notes in remark feeds
  11. An enumeration of submit slugs
  12. A Contributor+ saved cross-site scripting (XSS) problem in Fast Edit on websites with a lot of customers

Of these, three are in all probability of the very best/greater concern:

  1. Pre-auth XSS on the login display with potential PHP code execution
    That is confirmed to be rated as a excessive severity vulnerability.
  2. SSRF permitting requests to link-local ranges
    That is doubtlessly severe however there is no such thing as a details about it proper now to know for sure. SSRF means Server-Facet Request Forgery. For this context, link-local IP ranges are IP addresses which might be reserved for inner communication inside the server. Put all that collectively and the minimal description of this vulnerability implies that the vulnerability allows server-side requests to link-local IP ranges which might expose delicate data on the server. However there is no such thing as a description of this vulnerability, so we will solely infer from the naked data given.
  3. A privilege escalation problem on multisite networks with consumer registration enabled, permitting a consumer to create a brand new website.
    This vulnerability allows the unauthorized skill to create one other website on the community. That may very well be a difficulty for institutional websites like universities but additionally to these with multisite installations.

Excessive Severity Rated XSS Vulnerability

Fairly probably probably the most regarding vulnerability within the listing is the one described as a Pre-Auth XSS. XSS means Cross-Website Scripting.

The Open Worldwide Utility Safety Venture (OWASP) describes XSS like this:

“Cross-Website Scripting (XSS) assaults are a sort of injection, wherein malicious scripts are injected into in any other case benign and trusted web sites. XSS assaults happen when an attacker makes use of an online software to ship malicious code, usually within the type of a browser facet script, to a unique finish consumer. Flaws that enable these assaults to succeed are fairly widespread and happen anyplace an online software makes use of enter from a consumer inside the output it generates with out validating or encoding it.

An attacker can use XSS to ship a malicious script to an unsuspecting consumer. The top consumer’s browser has no solution to know that the script shouldn’t be trusted, and can execute the script. As a result of it thinks the script got here from a trusted supply, the malicious script can entry any cookies, session tokens, or different delicate data retained by the browser and used with that website.”

Pre-auth XSS on the login display with potential PHP code execution

That’s rated 8.9/10. That vulnerability is labeled as “Pre-auth” which signifies that an attacker doesn’t want a WordPress account to launch an assault, however that’s mitigated to a sure extent as a result of the exploitation nonetheless requires consumer interplay, somebody with an account on the location must be tricked into performing an motion (aka social engineering).

The official WordPress GitHub safety repo explains this vulnerability says that it might result in distant code execution (RCE):

“WordPress is weak to a pre-auth mirrored XSS vulnerability on the login display.

Through a specifically crafted malicious third-party web site hosted by an attacker, it’s doable for this to be escalated to an RCE vulnerability with situations outdoors of the attackers management. This requires profitable social engineering of and express interplay by the goal sufferer.

This problem impacts all variations of WordPress. Model 7.0.3 has been launched, containing a repair for the vulnerability, and as a courtesy to customers on older branches the repair has been backported to all branches again to 4.7.”

Oliver Sild of Patchstack tweeted on X concerning the XSS vulnerability:

“Weeks in the past when #WP2Shell dropped and OpenAI Sol Extremely took a lot of the credit score – all I thought of was how all the opposite labs and AI-pentest corporations will rush to show they’ll discover one thing within the WordPress core too.

Nicely, at present, 3 weeks later – we’ve got the following WordPress core model launch with not one, however 12 vulnerabilities being patched. And as anticipated, the problems have been reported by @AnthropicAI, @pwn_ai, @AikidoSecurity, and others.

The nastiest one is a login display XSS, which by way of some social engineering might result in Distant Code Execution. Fortunately, WordPress is auto-updating quick and not one of the vulnerabilities are mass-exploitable like WP2Shell was.

As all the time, @patchstackapp prospects obtained mitigation guidelines proper on the disclosure.”

Oliver Sild additionally advised Search Engine Journal that they’re monitoring if hackers are exploiting the XSS vulnerability:

“We’re monitoring whether or not it’s getting exploited, however seems just like the social engineering bit on the XSS that would result in RCE is probably not going to get a lot consideration from the hackers.”

Featured Picture by Shutterstock/Jihan Nafiaa Zahri

Tags: 7.0.3FixesHighreleaseSecurityseverityVulnerabilityWordPressXSS
Admin

Admin

Next Post
Canadian Man Pleads Responsible in Snowflake Extortions – Krebs on Safety

Canadian Man Pleads Responsible in Snowflake Extortions – Krebs on Safety

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

HomeBoost’s app will present you the place to avoid wasting in your utility payments

HomeBoost’s app will present you the place to avoid wasting in your utility payments

January 31, 2026
The Obtain: China’s producers’ viral second, and the way AI is altering creativity

The Obtain: China’s producers’ viral second, and the way AI is altering creativity

April 29, 2025

Trending.

Backrooms director Kane Parsons explains the birds, the portals, and his sensible results

Backrooms director Kane Parsons explains the birds, the portals, and his sensible results

May 31, 2026
100 Most Costly Key phrases for Google Advertisements in 2026

100 Most Costly Key phrases for Google Advertisements in 2026

January 13, 2026
The Full Information to EcoGPT

The Full Information to EcoGPT

June 6, 2026
Parental Lock Code Puzzle Defined

Parental Lock Code Puzzle Defined

July 27, 2025
29 Eye-Opening Google Search Statistics for 2025

29 Eye-Opening Google Search Statistics for 2025

July 10, 2025

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Canadian Man Pleads Responsible in Snowflake Extortions – Krebs on Safety

Canadian Man Pleads Responsible in Snowflake Extortions – Krebs on Safety

August 7, 2026
WordPress Safety Launch 7.0.3 Fixes Excessive Severity XSS Vulnerability

WordPress Safety Launch 7.0.3 Fixes Excessive Severity XSS Vulnerability

August 7, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved