AI Weekly Malaysia

Back to items Summaries

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

ID
26072
Status
new
Published
19 Sep 2026, 12:56 AM
Fetched
19 Sep 2026, 3:17 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Excerpt

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only

Summary

No summary yet. It will appear after the daemon summarizes this item.

Top