started · updated
Critical WordPress and 7‑Zip vulnerabilities prompt urgent updates
WordPress sites face two critical vulnerabilities that are already being exploited. Experts advise administrators to upgrade to WordPress version 6.9.5, 7.0.2 or later and to enable automatic updates for the core and all plugins.
The open‑source archive utility 7‑Zip also has a high‑risk flaw. Users should install the security update released by the developers, which secures versions 26.02 and newer. The German Federal Office for Security in Information Technology (BSI) recommends applying both patches immediately.
Updating promptly and turning on automatic updates will protect millions of websites and desktop users from active threats.