Kryptovalutaticker:
sysadmin från Cyber Security News

Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link

Guru Baran
Saturday at 04:30
5 Visningar
0 Kommentarer
Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link

WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into remote code execution (RCE) on a vulnerable website. The issue begins with a WordPress Core theme-preview weakness that silently installs an attacker-selected theme from the official directory, then becomes a server compromise when chained with insecure pre-activation code in a theme. WordPress addressed the Core flaw in version 7.1.1, released September 17, 2026, as part of an update containing 11 security fixes, 17 Core bug fixes, and 19 Block Editor fixes. The official advisory describes the issue as specially crafted URLs automatically installing and previewing an inactive...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!