ZeroHour
Vendor

pwn.ai

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

WordPress 7.1.1 patches Click2Shell, a flaw letting crafted links force-install themes on admin visits, chainable to remote code execution; no exploitation observed.

Researchers at pwn.ai disclosed Click2Shell, a WordPress core flaw where a crafted link, opened by a logged-in administrator, silently installs an attacker-chosen theme from WordPress.org using the admin's own session and security token. The forced install alone is rated CVSS 7.1; chained with an unauthenticated background download handler in the Mobile Repair Zone theme, it reaches CVSS 9.6 remote code execution. WordPress fixed the bug in 7.1.1 released September 17, with fixes backported to supported branches down to 4.7. No CVE has been assigned yet and there is no sign of exploitation, unlike the separate, CISA-listed wp2shell flaw.

The Hacker Newsupdated · 4h agofirst · 7h agoVulnerability 6 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.