
WordPress REST API Vulnerability is Being Actively Exploited, Hundreds of Thousands of Sites Defaced
At the end of January, WordPress 4.7.2 was released to fix four security issues, three of which were disclosed at the time of the release. These included a SQL injection vulnerability in WP_Query, a cross-site scripting (XSS) vulnerability in the posts list table, and the Press This feature allowing users without permission to assign taxonomy…












