A CSRF flaw in WordPress core lets unauthenticated attackers force admins to install malicious themes, enabling remote code execution on millions of sites. Version 7.1.1 patches https:// deafnews.it/e

A CSRF flaw in WordPress core lets unauthenticated attackers force admins to install malicious themes, enabling remote code execution on millions of sites. Version 7.1.1 patches https:// deafnews.it/en/article/wordpre ss-click2shell-one-admin-click-opens-rce-on-millions-of-sites

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

A CSRF flaw in WordPress core lets unauthenticated attackers force admins to install malicious themes, enabling remote code execution on millions of sites. Version 7.1.1 patches https:// deafnews.it/e

mastodon:infosec-exchangeother8d ago kagi ↗

A CSRF flaw in WordPress core lets unauthenticated attackers force admins to install malicious themes, enabling remote code execution on millions of sites. Version 7.1.1 patches https:// deafnews.it/en/article/wordpre ss-click2shell-one-admin-click-opens-rce-on-millions-of-sites