Thursday, 18 December 2025
25.6 C
Singapore
14.6 C
Thailand
25.2 C
Indonesia
26.8 C
Philippines

WordPress strengthens security with latest update

Learn how the latest WordPress update, version 6.4.2, tackles a critical security vulnerability to provide better website protection.

WordPress released version 6.4.2, specifically addressing a critical vulnerability in a proactive step to enhance digital security. This flaw, if exploited, could allow attackers to execute PHP code on the site, potentially leading to complete control over the affected websites.

The root of this issue traces back to a feature in WordPress 6.4, which was developed to improve HTML parsing within the block editor. Notably, this vulnerability is unique to versions 6.4 and 6.4.1, leaving earlier versions unaffected.

An official statement from WordPress highlights the gravity of the situation:

“A Remote Code Execution vulnerability that is not directly exploitable in core, however the security team feels that there is a potential for high severity when combined with some plugins, especially in multisite installs.”

Further insights from Wordfence, a renowned security firm, shed light on the potential risks:

“Since an attacker able to exploit an Object Injection vulnerability would have full control over the on_destroy and bookmark_name properties, they can use this to execute arbitrary code on the site to gain full control easily.

While WordPress Core currently does not have any known object injection vulnerabilities, they are rampant in other plugins and themes. The presence of an easy-to-exploit POP chain in WordPress core substantially increases the danger level of any Object Injection vulnerability.”

Importance of timely updates for enhanced protection

Despite Object Injection vulnerabilities being challenging to exploit, Wordfence emphasises the importance of updating WordPress to the latest version. WordPress itself underscores the urgency of these updates for improved site protection.

For more detailed information, refer to the official WordPress announcement: WordPress 6.4.2 Maintenance & Security Release.

Additionally, the Wordfence advisory provides further details: PSA: Critical POP Chain Allowing Remote Code Execution Patched in WordPress 6.4.2.

Hot this week

Cybersecurity threats and AI disruptions top concerns for IT leaders in 2026, Veeam survey finds

Veeam survey finds cybersecurity and AI risks dominate IT leaders’ concerns for 2026, with data resilience and sovereignty rising in priority.

Beastro blends cozy life sim with tactical deck-building combat

Beastro combines cozy farm-life sim gameplay with tactical deck-building combat in a charming, animal-filled world.

Google removes AI-generated Disney videos from YouTube after cease-and-desist

Google has removed AI-generated Disney character videos from YouTube after receiving a cease-and-desist letter over copyright claims.

PGL brings Counter-Strike 2 Major to Singapore in November 2026

PGL confirms the Counter-Strike 2 Major is coming to Singapore in November 2026, marking the first CS2 Major in Southeast Asia.

China Changan Automobile Group reaches 30 million vehicle milestone

China Changan Automobile Group marks its 30 millionth vehicle milestone, highlighting its EV strategy, safety focus, and global growth plans.

Huawei unveils Mate X7 foldable phone for global markets

Huawei unveils the global Mate X7 foldable phone in Dubai, detailing design updates, camera improvements, software limits and premium pricing.

Dishonored and Deus Ex lead reflects on Arkane Austin’s closure

Harvey Smith reflects on Arkane Austin’s closure, Redfall’s challenges, and the human cost of layoffs in today’s games industry.

LG introduces Micro RGB evo TV ahead of CES 2026

LG unveils its first Micro RGB evo TV for CES 2026, promising wider colour gamut, higher brightness, and LCD performance closer to OLED.

Apple’s next AirTag could introduce major upgrades to tracking and battery features

Apple’s next AirTag may bring improved pairing, longer tracking range and better battery reporting, based on features found in iOS 26.

Related Articles

Popular Categories