New WordPress 'Click2Shell' Flaw Forces Theme Installs, Can Chain to Code Execution
ID: 37ba11e9-72dd-5da7-87f7-ca0b85af5787
STIX ID: report--37ba11e9-72dd-5da7-87f7-ca0b85af5787
Feed Name: CosmicBytez Labs
WordPress released version 7.1.1 to address "Click2Shell," a parsing discrepancy that lets a crafted link cause background, silent theme installations when a logged-in administrator opens it; security researchers showed that chaining this forced-install primitive with a vulnerable "Mobile Repair Zone" theme lacking permission checks can escalate to full remote code execution (CVSS up to 9.6). Affected WordPress core versions include 6.0 through the pre-patch release; recommended actions are immediate update to 7.1.1 (or backported security releases), auditing for unexpected inactive themes, and removing or updating any instances of Mobile Repair Zone.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
