Tech Times·10 min read

WordPress Click2Shell Flaw Silently Installs Themes via Crafted Admin Link

M
Mark Rutherford
WordPress Click2Shell Flaw Silently Installs Themes via Crafted Admin Link
Dive DeeperCreate a free account to unlock

A single crafted link sent to a logged-in WordPress administrator can silently install an attacker-chosen theme on the target site - no Install button click required - and that installed theme can then be turned into a server-level foothold within seconds. WordPress patched the underlying flaw on September 17 in version 7.1.1, but public working exploit code landed on GitHub the following day, collapsing the effective patching window for self-hosted sites still running vulnerable builds.Security research firm pwn.ai, which discovered and reported the vulnerability, disclosed the full attack chain on September 18 and named it Click2Shell to describe its end goal: a single malicious link, opened by any site administrator, that ultimately delivers a remote shell on the target server.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in