Click2Shell: WordPress Flaw Enables RCE Chain
SOCRadar describes Click2Shell, a WordPress Core flaw that can chain a tricked admin browser into RCE.
SOCRadar describes Click2Shell as a WordPress Core vulnerability that can manipulate a logged-in administrator's browser into installing and previewing a theme without explicit consent. That action is presented as part of a remote code execution chain. The excerpt does not name a CVE or say the flaw is being exploited.
- Click2Shell is described as a WordPress Core flaw
- It manipulates a logged-in administrator's browser
- The chain can install and preview a theme toward RCE
- The excerpt cites no CVE and no active exploitation
Click2Shell: WordPress Flaw Enables RCE Chain Click2Shell is a vulnerability in WordPress Core that allows a logged-in administrator's browser to be manipulated into installing and previewing a theme without explicit con
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.