National Cyber Warfare Foundation (NCWF)

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution


0 user ratings
2026-09-18 17:48:05
milo
Blue Team (CND)
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.

The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.