WordPress vulnerabilities–path traversal + local file inclusion = remote code execution:
https://blog.ripstech.com/2019/wordpress-image-remote-code-execution/
– the vulnerability was there for 6 years
– fixed in WordPress 4.9.9 and 5.0.1, however, path traversal is still possible under certain circumstances
#wordpress #vulnerability #cms #infosec #security #cybersecurity #rce