CyberNotableSingle-sourceDeveloping
4.8
WordPress Click2Shell CSRF flaw allows PHP execution; PoC published
BleepingComputerLO·about 23 hours ago
WordPress released a security patch for a vulnerability dubbed 'Click2Shell' that allows attackers to automatically install and preview themes, potentially leading to remote code execution. The flaw affects a widely used content management system, and while details are limited, the potential for RCE on unpatched sites is significant. The patch's availability and the vulnerability's exploitation status remain unclear.