Wednesday, 16 July 2025
28.1 C
Singapore
29 C
Thailand
18.6 C
Indonesia
29 C
Philippines

WordPress strengthens security with latest update

Learn how the latest WordPress update, version 6.4.2, tackles a critical security vulnerability to provide better website protection.

WordPress released version 6.4.2, specifically addressing a critical vulnerability in a proactive step to enhance digital security. This flaw, if exploited, could allow attackers to execute PHP code on the site, potentially leading to complete control over the affected websites.

The root of this issue traces back to a feature in WordPress 6.4, which was developed to improve HTML parsing within the block editor. Notably, this vulnerability is unique to versions 6.4 and 6.4.1, leaving earlier versions unaffected.

An official statement from WordPress highlights the gravity of the situation:

“A Remote Code Execution vulnerability that is not directly exploitable in core, however the security team feels that there is a potential for high severity when combined with some plugins, especially in multisite installs.”

Further insights from Wordfence, a renowned security firm, shed light on the potential risks:

“Since an attacker able to exploit an Object Injection vulnerability would have full control over the on_destroy and bookmark_name properties, they can use this to execute arbitrary code on the site to gain full control easily.

While WordPress Core currently does not have any known object injection vulnerabilities, they are rampant in other plugins and themes. The presence of an easy-to-exploit POP chain in WordPress core substantially increases the danger level of any Object Injection vulnerability.”

Importance of timely updates for enhanced protection

Despite Object Injection vulnerabilities being challenging to exploit, Wordfence emphasises the importance of updating WordPress to the latest version. WordPress itself underscores the urgency of these updates for improved site protection.

For more detailed information, refer to the official WordPress announcement: WordPress 6.4.2 Maintenance & Security Release.

Additionally, the Wordfence advisory provides further details: PSA: Critical POP Chain Allowing Remote Code Execution Patched in WordPress 6.4.2.

Hot this week

Google unveils new AI tools for marketing on Search and YouTube at Southeast Asia event

Google launches new AI tools across Search and YouTube at GML SEA to help marketers boost creative output, reach, and ad performance.

Google plans to merge ChromeOS and Android into one unified platform

Google confirms plans to combine Android and ChromeOS into one platform, bringing big changes to phones, laptops, and tablets.

iPhone 17 Air may launch in a stunning new blue shade you’ve never seen before

Apple may debut a subtle new light blue finish for the iPhone 17 Air, possibly shared by the Pro, launching this September.

Nintendo Switch OLED drops to US$249 during Prime Day

Get the Nintendo Switch OLED for just US$249 during Prime Day, plus bundle and accessory discounts for a complete gaming setup.

BDx unveils Southeast Asia’s first hybrid quantum AI testbed in Singapore

BDx launches Southeast Asia’s first hybrid quantum AI testbed in Singapore, boosting AI innovation and sustainability at the SIN1 data centre.

Southeast Asia’s enterprise AI evolution enters a new phase

To mark AI Appreciation Day 2025, we gathered insights from senior technology leaders across Southeast Asia to explore how enterprises are scaling AI responsibly and strategically.

Google plans to merge ChromeOS and Android into one unified platform

Google confirms plans to combine Android and ChromeOS into one platform, bringing big changes to phones, laptops, and tablets.

Apple accused of stalling browser competition on iOS despite EU ruling

Apple faces backlash over iOS browser rules as developers struggle to launch non-WebKit engines despite the EU’s DMA ruling.

Microsoft will stop new Office 365 features on Windows 10 in 2026

Microsoft will stop new Microsoft 365 features for Windows 10 users starting August 2026, with full support ending by early 2027.

Related Articles

Popular Categories