CyberHighConfirmedDeveloping
9.3
Unpatched Kaltura mwEmbed vulnerabilities enable unauthenticated RCE and file exposure
The Hacker News·about 11 hours ago
A vulnerability chain in the Avada theme allows unauthenticated attackers to execute arbitrary PHP code, potentially compromising millions of WordPress sites. The extent of active exploitation remains unconfirmed, but the flaw's severity necessitates immediate patching to prevent widespread server takeovers.