Story thread · 3 reports / 3 sources

WordPress Click2Shell flaw lets hackers execute PHP on the server

bleepingcomputer.com · 15h · first report

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]

The coverage

  1. Security updates: Click2Shell vulnerability to compromise WordPress websites

    heise.de · 2h

  2. WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

    thehackernews.com · 4h

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.