Security researchers from RIPS today announced a security flaw in WordPress, one of the most popular content management systems (CMS). The researchers say they have been informing the WordPress team since November 2017, but WordPress developers have not yet released an update.

The vulnerability affects the core of WordPress, not any of its plugins. More specifically, the bug is in a PHP function that deletes thumbnails from images uploaded to the site.
Researchers discovered that users who have access to the article editor, and can upload and delete images (including their thumbnails), can inject malicious code into the site and delete critical files, something that should not be possible without access to the FTP server.
The size of the vulnerability is fortunately limited as not all users have access to the editor. However, using the malicious code, it is possible to delete the wp-login.php file, which is the site's configuration file. Once deleted, anyone can re-run the installation process, locking out administrators. This way, the attacker can "steal" the entire site and become an administrator, allowing them to publish malicious content, redirect users to another site, or even delete the website entirely. Below is a detailed video from the team themselves performing the entire process in less than 1 minute.
