Skip to main content

Share story

Security

WordPress fixes Click2Shell flaw as proof-of-concept code becomes public

WordPress fixes Click2Shell flaw as proof-of-concept code becomes public Image: Primary
Technical details and proof-of-concept code were published for Click2Shell, a WordPress Core vulnerability fixed in version 7.1.1. The attack chain can make a logged-in administrator's browser install a vulnerable catalog theme and execute its PHP code on the server, even though the attacker needs no WordPress account. Successful exploitation could expose user data and configuration secrets, modify files or create rogue administrators. The flaw affects WordPress Core 7.1.0 and earlier, but the administrator must visit a crafted link and lower-privileged Author or Editor accounts cannot trigger the chain.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Greenberg Traurig clients sue over data breach

A proposed class of Greenberg Traurig clients has sued the law firm in New York federal court, alleging that it failed to protect their personal information before a preventable data breach. The plaintiffs also allege that the fir...

Security AI
Security AI

Meta's Muse assistant exposed account-control token through local apps

A zero-day vulnerability in Meta's Muse assistant lets any locally installed app or terminal command redirect the service's transcription endpoint and capture the token that controls a user's Muse account, Ars Technica reported. T...

Science Security
Science Security

Three-user quantum-key experiment withstands 59.6 dB system loss

Researchers at Nanjing University experimentally generated a shared secure key for three users under total system loss of approximately 59.6 dB, compared with approximately 21.5 dB in the group's earlier measurement-device-indepen...