CyberSecurity News
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
AI summary
WordPress has released patches for vulnerabilities in its core software, including one that allows a malicious link to install a theme from the official WordPress directory without user interaction when opened by a logged-in administrator. This flaw is part of an attack chain referred to as Click2Shell by the security firm pwn.ai, which reported the issue. The vulnerability can be triggered by a crafted web link. On its own, the flaw has limited impact.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

