Skip to main content

Tag: click2shell

1 article

WordPress admin dashboard on laptop with theme installation page.

WordPress Patches Click2Shell Flaw That Forces Theme Installs

A simple click on a crafted link by a logged-in administrator could allow an attacker to silently install a malicious theme and execute code on your server, thanks to a high-impact vulnerability in WordPress dubbed Click2Shell. This security flaw exploits a discrepancy in how WordPress and the WordPress.org directory interpret web links.

Analyst 207