Click2Shell: Preauth WordPress Core Theme Preview Injection to RCE Chain
pwn.ai | vulnerability | #ai-security | #rce | #wordpress | #vulnerability | #patch | #security-release | #preauth | #theme-injection
Summary
pwn.ai chained a pre-auth theme preview injection in WordPress Core with a flaw in the mobile-repair-zone catalog theme to achieve unauthenticated RCE via a single crafted link. Fixed in the WordPress 7.1.1 security release; CVE pending.
- Collected
Skip to content