WordPress patched Click2Shell, reported by pwn.ai, which forces a logged-in admin browser to install and preview an attacker-chosen theme from WordPress.org. It does not allow arbitrary upload alone,

WordPress patched Click2Shell, reported by pwn.ai, which forces a logged-in admin browser to install and preview an attacker-chosen theme from WordPress.org. It does not allow arbitrary upload alone, but chained it enables code execution, so prioritize core updates and admin session hygiene. # WordPress # Click2Shell # AppSec https:// cyberworldops.eu/en/click2shel l-turns-a-wordpress-admin-visit-

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

WordPress patched Click2Shell, reported by pwn.ai, which forces a logged-in admin browser to install and preview an attacker-chosen theme from WordPress.org. It does not allow arbitrary upload alone,

mastodon:infosec-exchangeother10d ago kagi ↗

WordPress patched Click2Shell, reported by pwn.ai, which forces a logged-in admin browser to install and preview an attacker-chosen theme from WordPress.org. It does not allow arbitrary upload alone, but chained it enables code execution, so prioritize core updates and admin session hygiene. # WordPress # Click2Shell # AppSec https:// cyberworldops.eu/en/click2shel l-turns-a-wordpress-admin-visit-