New WordPress Click2Shell flaw forces theme installs, can chain to code execution
WordPress released patches for a new set of core vulnerabilities. The Click2Shell chain allows installing a theme from the official WordPress.org directory without clicking the Install button, requiring only that an administrator opens a specially crafted link. The vulnerability can lead to arbitrary code execution.
- Patches close new set of WordPress core vulnerabilities
- Click2Shell attack installs theme without clicking button
- Logged-in admin only needs to open malicious link
- Chain can lead to arbitrary code execution
Read next
Security