Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Click2Shell: Preauth WordPress Core Theme Preview Injection to RCE Chain

Summary

pwn.ai chained a pre-auth theme preview injection in WordPress Core with a flaw in the mobile-repair-zone catalog theme to achieve unauthenticated RCE via a single crafted link. Fixed in the WordPress 7.1.1 security release; CVE pending.
Collected

original ↗