Crypto Ticker:
sysadmin from Cyber Security News

Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link

Guru Baran
Saturday at 04:30
4 Views
0 Comments
Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link

WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into remote code execution (RCE) on a vulnerable website. The issue begins with a WordPress Core theme-preview weakness that silently installs an attacker-selected theme from the official directory, then becomes a server compromise when chained with insecure pre-activation code in a theme. WordPress addressed the Core flaw in version 7.1.1, released September 17, 2026, as part of an update containing 11 security fixes, 17 Core bug fixes, and 19 Block Editor fixes. The official advisory describes the issue as specially crafted URLs automatically installing and previewing an inactive...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!