Summary
WordPress 7.1.1 patches 11 security flaws, including the "Click2Shell" exploit chain that allows unauthenticated attackers to gain remote code execution by tricking an administrator into clicking a malicious link.
Take Action:
Update WordPress to version 7.1.1 right away. The exploit chain exposes your WordPress when an admin simply clicks on a bad link. Fixes are also backported down to 4.7 if you're on an older branch. If you can't update today, keep admin accounts to a minimum, never open unknown links while logged into wp-admin, delete unused themes, and check your site for themes or plugins you didn't install.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)