New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

High · The Hacker News ·

WordPress

What happened

WordPress patched core flaws; a crafted link opened by a logged-in admin can silently install a WordPress.org theme, called Click2Shell, and may chain to code execution. Affected: WordPress sites/admins.

What to do now

Patch WordPress core immediately to the latest release; verify version. Enforce MFA, limit admin accounts, review/remove unknown themes, monitor logs for theme installs. Don't open untrusted links while logged in. If delayed, restrict admin access/WAF. Verify with vendor advisory.

Original source

The Hacker News

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news