Mmastodon TechnologyCybersecurity first seen 8 h ago, last 8 h ago, peak #11
WordPress Flaw Turns One Admin Click Into Server Takeover
Original: Click2Shell: A WordPress Theme-Install Flaw That Turns One Admin Click Into Server Code Execution If your organisation r
Security researchers have disclosed a WordPress vulnerability, dubbed Click2Shell, in which a single link opened by a site administrator can trigger malicious theme installation and full remote code execution on the server. Because WordPress powers a large share of websites, organisations are being urged to review admin practices and apply patches.
Why now: The flaw's severity and WordPress's huge install base make it a pressing concern for site owners and administrators.
WordPressClick2ShellInsomnisec
Evidence
- Click2Shell: A WordPress Theme-Install Flaw That Turns One Admin Click Into Server Code Execution If your organisation runs a website, there is a strong chance it runs on WordPress, and a flaw disclosed in September means a single link, opened by one of your own administrators,… · insomnisec@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/678215