A high-severity vulnerability in the All-in-One WP Migration and Backup WordPress plugin exposes over 3 million websites to remote code execution (RCE) attacks
Probably a dumb question, but couldn’t they just use this exploit to remotely patch itself?
Edit; after a quick thought, I suppose Wordpress instances don’t phone home so Defiant has no idea who has a Wordpress instance running and who doesn’t.
Probably a dumb question, but couldn’t they just use this exploit to remotely patch itself?
Edit; after a quick thought, I suppose Wordpress instances don’t phone home so Defiant has no idea who has a Wordpress instance running and who doesn’t.