{ads}

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution



September 18, 2026 at 10:26PM

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only

from The Hacker News https://ift.tt/ntvGTgW

0 Response to "New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution"

Post a Comment

Article Top Ads

Central Ads Article 1

Middle Ads Article 2

Article Bottom Ads