< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 16 sources · 4 days · First seen · Last updated

WordPress security vulnerabilities and patches

Overview

Security researchers identified critical vulnerabilities in the WordPress content management system, leading to the release of security update version 7.1.1.

One major flaw, known as ‘Click2Shell’, allows for remote code execution (RCE). This vulnerability, discovered by Paulos Yibelo of pwn.ai, exploits the theme-preview function by using specially crafted URLs to trick logged-in administrators into silently installing an inactive theme. Attackers can then chain this with a second vulnerability within a specific theme, such as ‘Mobile Repair Zone 2.5.4’, to execute malicious code on the server.

A second vulnerability, nicknamed ‘wp2shell’, enables attackers to take control of websites without a password. In observed attacks, this exploit was used to quietly create unauthorized administrator accounts on unpatched sites.

Following the initial 7.1.1 maintenance release, which addressed 11 vulnerabilities including stored cross-site scripting (XSS), authenticated path traversal, and authorization bypasses, the WordPress team issued version 7.1.2. This subsequent dedicated security release specifically addresses a critical path traversal vulnerability that could also facilitate remote code execution. Security experts urge all administrators to update installations immediately to prevent unauthorized access.

Entities

WordPress · Anthropic · WordPress.org · Mobile Repair Zone · pwn.ai

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 1 day ago

    [TECHNOLOGY] 6 sources
    WordPress releases security updates to patch critical Click2Shell vulnerability

    WordPress has issued urgent security updates, including versions 7.1.1 and 7.1.2, to patch critical vulnerabilities like “Click2Shell” that allow remote code execution via malicious links.

  2. 5 days ago

    [TECHNOLOGY] 10 sources
    WordPress releases security update to patch Click2Shell RCE vulnerability

    WordPress released version 7.1.1 to patch the ‘Click2Shell’ vulnerability, which can lead to remote code execution via malicious theme-preview URLs.

Sources

appinn.com · blogspan.net · cyberinsider.com · cybernoz.com · es.wordpress.org · flagthis.com · it-boltwise.de · ithome.com · paraonline.com.br · reclaimhosting.com · sadio.org.ar · singaporebestwebdesign.com · turbolab.it · upday.com · wordpress.org · wpde.org

This summary has been updated 1 time: see revision history