Hello teammates!
INCIBE has published an advisory about a vulnerability of high severity that affects a long list of WordPress versions. This flaw allows unrestricted file uploads, which could lead to remote code execution on your site.
The affected versions are numerous, practically all branches from 4.7 up to 7.0. The full list is at the link I share below.
You need to update WordPress to the patched version corresponding to your branch. For example, if you’re using 7.0, you should update to 7.0.4.
Here is the full INCIBE advisory: Unrestricted file uploads in WordPress
If you have any questions, we’re here ![]()
Sergio Turpín