New Security Issue for WP 6.9

Not sure if you guys are aware of the recent WP security fix but apparently it affects WP 6.9 also.

An authenticated Author+ remote code execution issue via malicious file upload on sites that use Imagick and Ghostscript reported by the team at pwn.ai

As a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.

  • WordPress 6.9 is affected by this vulnerability. Version 6.9.7 has been released containing a fix.

Thanks for reporting this, the community was already aware.

This specific security issue does not affect CP directly since v2 was a refork of the 6.3 branch that according to the official WP announcement was not affected by the issue.

However, CP 2.7.1 was released very recently in response to other recently discovered vulnerabilities that WP has fixed and affect CP too.

2 Likes

This issue was back ported through multiple WordPress versions and was also included in the most recent ClassicPress version.

2 Likes