• ohshit604@lemmy.halstead.host
    link
    fedilink
    English
    arrow-up
    1
    ·
    7 days ago

    A high-severity vulnerability in the All-in-One WP Migration and Backup WordPress plugin exposes over 3 million websites to remote code execution (RCE) attacks

    Probably a dumb question, but couldn’t they just use this exploit to remotely patch itself?

    Edit; after a quick thought, I suppose Wordpress instances don’t phone home so Defiant has no idea who has a Wordpress instance running and who doesn’t.