Tag: server side vulnerability
2 articles

WordPress Flaw Exposes Servers to Remote Code Execution
A newly discovered WordPress vulnerability, dubbed Click2Shell, can be exploited to execute remote code on servers, and security researchers have already published technical details and a proof-of-concept. This critical flaw was patched in WordPress 7.1.1, but earlier versions remain vulnerable.

Atlassian Rovo Exposes Data Risk Via Prompt Injection Flaw
A critical flaw in Atlassian's Rovo assistant could allow attackers to siphon off sensitive Jira and Confluence data, thanks to a prompt injection vulnerability that two separate security teams were able to exploit. Fortunately, Atlassian has patched one of the two paths used to carry out the attack, but the incident highlights the risks of data exposure via AI-powered tools.