WordPress Click2Shell flaw lets hackers execute PHP on the server

WordPress Click2Shell flaw lets hackers execute PHP on the server
A new WordPress Core CSRF chain dubbed Click2Shell can let an attacker force-install a theme and achieve pre-authenticated remote code execution when a logged-in administrator visits a crafted link. WordPress fixed the issue in version 7.1.1, and researchers have already published full technical details and a proof-of-concept exploit. #Click2Shell #WordPress #pwn.ai #PaulosYibelo

Keypoints

  • Click2Shell is a WordPress Core CSRF vulnerability chain.
  • The flaw can lead to pre-authenticated remote code execution.
  • An administrator must visit a crafted URL for the exploit to work.
  • The attack can force-install themes from the WordPress.org catalog.
  • WordPress version 7.1.1 fixes the vulnerability by tightening theme slug handling.

Read More: https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/