WordPress patched 11 vulnerabilities last week, including Click2Shell, a flaw that could allow remote code execution through specially crafted theme-preview URLs. pwn.ai found that an unauthenticated attacker could force installation of an attacker-selected theme and potentially execute PHP code on the server, earning a $300 bug bounty for the report. #Click2Shell #WordPress #pwn.ai
Keypoints
- WordPress fixed 11 security vulnerabilities in version 7.1.1.
- Click2Shell could enable remote code execution through malicious theme-preview URLs.
- The flaw may let attackers force installation of an attacker-selected theme without authentication.
- Over 40 third-party WordPress themes could be abused for PHP code execution while inactive.
- WordPress also backported the fixes to older versions, including WordPress 4.7.
Read More: https://www.securityweek.com/wordpress-patches-click2shell-vulnerability/