Nuacht

We have been made aware that the Advanced Custom Fields plugin on the WordPress directory has been taken over by WordPress dot org.
The WordPress WP HTML Mail plugin for personalized emails is vulnerable to code injection and phishing due to XSS.
The patch implements a permission check on the custom REST API endpoint and incorporates file type and extension checks using the wp_check_filetype_and_ext function. In light of these findings, users ...