A vulnerability in WordPress allows a remote, authenticated attacker to execute arbitrary code. The flaw stems from a bug that permits uploading a malicious PostScript file to the affected WordPress installation.
What Makes This Vulnerability Noteworthy?
The attacker must be authenticated, meaning they need a valid account on the WordPress instance. That reduces the attack surface, but does not eliminate it: compromised accounts, weak passwords, or open user registration can give attackers the access they need.
What to Do Now
Update WordPress to the current version via the WordPress admin dashboard under Updates. Also check whether unused accounts with elevated roles, such as Author, Editor, or Administrator, still exist and remove them. Apply file upload restrictions as tightly as your setup allows and periodically audit uploaded files on your server.