WordPress Patches ‘Click2Shell’ Vulnerability

https://www.securityweek.com/wp-content/uploads/2024/08/WordPress.jpeg

WordPress last week released patches for 11 vulnerabilities, including a flaw that could potentially lead to remote code execution (RCE).

Dubbed Click2Shell, the flaw does not have a CVE identifier yet. In its advisory, WordPress explains that it could be exploited via specially crafted URLs to automatically install and preview inactive themes.

While this may sound relatively harmless, it is not: the inactive theme can be leveraged for RCE, according to pwn.ai, which was credited with finding and reporting the bug.

The issue, it explains, exists because a value in the WordPress theme-preview URL is interpreted differently by the themes API and by the JavaScript running in an administrator’s browser.

“The API reduces the value to an ordinary theme slug. The browser retains the original punctuation and places it inside a jQuery selector,” pwn.ai explains.

This allows an unauthenticated attacker to force the installation of an attacker-selected theme on...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE