A new vulnerability, dubbed "Click2Shell," has been identified in WordPress Core affecting versions 7.1.0 and earlier, as well as related branches. This allows an attacker to potentially execute arbitrary PHP code on a server by luring an administrator to a crafted URL, leading to automatic theme installation and exploitation of a vulnerable theme. Organizations using WordPress should prioritize updating to the latest patched version and reviewing theme and plugin installation practices to mitigate the risk of server compromise.
Read the full article at DEV Community
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.



