Skip to main content

Tag: wordpress vulnerability

2 articles

WordPress admin dashboard on laptop with theme installation page.

WordPress Patches Click2Shell Flaw That Forces Theme Installs

A simple click on a crafted link by a logged-in administrator could allow an attacker to silently install a malicious theme and execute code on your server, thanks to a high-impact vulnerability in WordPress dubbed Click2Shell. This security flaw exploits a discrepancy in how WordPress and the WordPress.org directory interpret web links.

Analyst 207
Vulnerable WordPress site setup with laptop, router, and modem on a minimalist desk.

WordPress Sites Targeted as Public Exploits Emerge for wp2shell Flaws

A critical vulnerability in WordPress Core, dubbed "wp2shell," has been discovered, allowing hackers to remotely execute code on affected sites - putting your online presence at risk if you haven't updated yet. Immediate action is urged for site operators to protect against this high-severity threat.

Analyst 207