🐛 WordPress vulnerability: Unrestricted file uploads in WordPress

Hello teammates!

INCIBE has published an advisory about a vulnerability of high severity that affects a long list of WordPress versions. This flaw allows unrestricted file uploads, which could lead to remote code execution on your site.

The affected versions are numerous, practically all branches from 4.7 up to 7.0. The full list is at the link I share below.

You need to update WordPress to the patched version corresponding to your branch. For example, if you’re using 7.0, you should update to 7.0.4.

Here is the full INCIBE advisory: Unrestricted file uploads in WordPress

If you have any questions, we’re here :wink:
Sergio Turpín

Thank you @sturpin

Thanks a lot @sturpin!
At first glance I'm not affected because I block it via an Apparmor / PHP FPM config.
But I'll check the infra right away.