Story thread · 2 reports / 2 sources

WordPress Click2Shell Flaw Silently Installs Themes via Crafted Admin Link

techtimes.com · 2h

WordPress Click2Shell Flaw Silently Installs Themes via Crafted Admin Link

How the coverage leans

Across 2 sources · syndicated copies counted once

WordPress Click2Shell vulnerability lets attackers silently install themes on any admin's site via a single crafted link, then chain to full server-level code execution. WordPress patched the flaw in version 7.1.1 on September 17, but public working exploit code hit GitHub the following day, leaving self-hosted sites in a narrow window to patch.

First report: New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution thehackernews.com, 1d

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.