
Click2Shell WordPress Flaw Lets Attackers Execute PHP Code and Take Over Websites
A newly disclosed WordPress Core vulnerability chain, dubbed Click2Shell, allowed unauthenticated attackers to force a logged-in Administrator’s browser to silently install a malicious theme and ultimately achieve remote code execution (RCE) with a single malicious link click. Security researchers at PWNAI discovered that WordPress’s theme-preview URL parameter is interpreted inconsistently by two different components. The […]
The post Click2Shell WordPress Flaw Lets Attackers Execute PHP Code and Take Over Websites appeared first on Cyber Security News.