New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
7 Articles
7 Articles
It is enough that a connected WordPress administrator opens an trapped link so that installs a theme of the official directory chosen by the attacker. If this theme is poorly protected, the attacker can then execute code on the server. The WordPress team has fixed this Click2Shell flaw in version 7.1.1, published on September 17.
WordPress Click2Shell Forces Theme Install, Chains to RCE
WordPress released patches on September 17 addressing Click2Shell, a high-severity vulnerability allowing attackers to force theme installations from specially crafted links without requiring user interaction beyond opening the malicious URL. The vulnerability works when logged-in administrators open attacker-crafted links, with neither clicking nor typing passwords necessary once they reach the page. Security researchers at pwn.ai […]
Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link
WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into remote code execution (RCE) on a vulnerable website. The issue begins with a WordPress Core theme-preview weakness that silently installs an attacker-selected theme from the official directory, then becomes a server compromise when chained […]
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium









