A critical vulnerability in the Next.js ImageResponse feature could allow attackers to execute code on a server using specially crafted SVG input.
WordPress has issued updates to fix the ‘Click2Shell’ vulnerability, a flaw that allows unauthenticated attackers to potentially execute remote code.
WordPress has introduced automated security reviews for plugin releases to identify malicious code and vulnerabilities before they reach users through the update API.