WordPress ships an emergency fix for a pre-auth XSS chain that ends in PHP code execution.
A pre-auth XSS chain that needs only a crafted username ends in PHP code execution on stock installs.
cPanel and WHM have released emergency patches for three vulnerabilities that could allow attackers to compromise web hosting environments through…