πŸ€– WordPress 'Click2Shell' (no CVE): pre-auth RCE chain via CSRF in Core. A crafted theme-preview URL installs a theme from the WordPress.org catalog β€” even inactive, it executes PHP during Customizer

πŸ€– WordPress 'Click2Shell' (no CVE): pre-auth RCE chain via CSRF in Core. A crafted theme-preview URL installs a theme from the WordPress.org catalog β€” even inactive, it executes PHP during Customizer preview. PoC published; patched in 7.1.1. Found by pwn.ai's Paulos Yibelo. πŸ”— https://www. bleepingcomputer.com/news/secu rity/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/ # Wor

1 reportother

Claim audit

No BS check run yet β€” press βš– to extract this story's claims and verify them against independent sources.

All coverage

πŸ€– WordPress 'Click2Shell' (no CVE): pre-auth RCE chain via CSRF in Core. A crafted theme-preview URL installs a theme from the WordPress.org catalog β€” even inactive, it executes PHP during Customizer

mastodon:infosec-exchangeother8d ago kagi β†—

πŸ€– WordPress 'Click2Shell' (no CVE): pre-auth RCE chain via CSRF in Core. A crafted theme-preview URL installs a theme from the WordPress.org catalog β€” even inactive, it executes PHP during Customizer preview. PoC published; patched in 7.1.1. Found by pwn.ai's Paulos Yibelo. πŸ”— https://www. bleepingcomputer.com/news/secu rity/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/ # Wor