Story thread · 2 reports / 2 sources
WordPress Click2Shell Flaw Silently Installs Themes via Crafted Admin Link
techtimes.com · 2h

How the coverage leans
Across 2 sources · syndicated copies counted once
WordPress Click2Shell vulnerability lets attackers silently install themes on any admin's site via a single crafted link, then chain to full server-level code execution. WordPress patched the flaw in version 7.1.1 on September 17, but public working exploit code hit GitHub the following day, leaving self-hosted sites in a narrow window to patch.
First report: New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution — thehackernews.com, 1d
The conversation · 0
Sign in to join the conversation.
No comments yet — start the thread.