Blog post

WordPress 5.1 CSRF to Remote Code Execution

Simon Scannell photo

Simon Scannell

Vulnerability Researcher

This blog post reveals another critical exploit chain for WordPress 5.1 that enables an unauthenticated attacker to gain remote code execution (CVE-2019-9787).