Skip to main content

Tag: server side vulnerability

2 articles

WordPress admin dashboard on a laptop in a home office with papers and notebook nearby.

WordPress Flaw Exposes Servers to Remote Code Execution

A newly discovered WordPress vulnerability, dubbed Click2Shell, can be exploited to execute remote code on servers, and security researchers have already published technical details and a proof-of-concept. This critical flaw was patched in WordPress 7.1.1, but earlier versions remain vulnerable.

Analyst 207
Modern office setting with laptop on desk and blurred screen.

Atlassian Rovo Exposes Data Risk Via Prompt Injection Flaw

A critical flaw in Atlassian's Rovo assistant could allow attackers to siphon off sensitive Jira and Confluence data, thanks to a prompt injection vulnerability that two separate security teams were able to exploit. Fortunately, Atlassian has patched one of the two paths used to carry out the attack, but the incident highlights the risks of data exposure via AI-powered tools.

Analyst 207