New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
Overview
WordPress has patched several vulnerabilities in its core software, including a serious flaw that could let attackers install themes from the official WordPress.org directory without user consent. This vulnerability, dubbed Click2Shell by researchers at pwn.ai, specifically affects logged-in administrators who click on a specially crafted link. While the flaw requires user interaction to exploit, it poses significant risks as it could lead to unauthorized code execution on compromised sites. Website owners using WordPress should ensure they update their installations promptly to protect against potential exploitation. The discovery of this vulnerability emphasizes the ongoing need for vigilance in web application security.
Key Takeaways
- Affected Systems: WordPress core software, specifically affects logged-in administrators.
- Action Required: WordPress has released patches to fix the vulnerabilities.
- Timeline: Newly disclosed
Original Article Summary
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only
Impact
WordPress core software, specifically affects logged-in administrators.
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
WordPress has released patches to fix the vulnerabilities. Users are advised to update to the latest version of WordPress as soon as possible.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Exploit, Vulnerability, Update.