DEV Community

Cover image for Click2Shell Exploit Chain Grants RCE on WordPress via Malicious Links
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Click2Shell Exploit Chain Grants RCE on WordPress via Malicious Links

Summary

WordPress 7.1.1 patches 11 security flaws, including the "Click2Shell" exploit chain that allows unauthenticated attackers to gain remote code execution by tricking an administrator into clicking a malicious link.

Take Action:

Update WordPress to version 7.1.1 right away. The exploit chain exposes your WordPress when an admin simply clicks on a bad link. Fixes are also backported down to 4.7 if you're on an older branch. If you can't update today, keep admin accounts to a minimum, never open unknown links while logged into wp-admin, delete unused themes, and check your site for themes or plugins you didn't install.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)