WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into remote code execution (RCE) on a vulnerable website. The issue begins with a WordPress Core theme-preview weakness that silently installs an attacker-selected theme from the official directory, then becomes a server compromise when chained with insecure pre-activation code in a theme. WordPress addressed the Core flaw in version 7.1.1, released September 17, 2026, as part of an update containing 11 security fixes, 17 Core bug fixes, and 19 Block Editor fixes. The official advisory describes the issue as specially crafted URLs automatically installing and previewing an inactive...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!