WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
A crafted comment (Comment2Shell) allowed an attacker to run code on the server via a line break in an HTML attribute. Another flaw, Click2Shell, enabled theme installation and further code execution. WordPress has had…
Two separate security flaws: Comment2Shell allowing code execution via comments and Click2Shell enabling theme installation. These were patched in the latest WordPress releases and are considered exploitable issues.
70