SecurityUnverified

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only

What happened

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only

Why it matters

The launch may affect adoption and competitive positioning for Security; usage evidence is the next signal to watch.

Affected entities

View evidence

1 reports · 1 original report · 1 independent

  1. The Hacker NewsPrimary source · Supports · EN · 100%
    New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

Claims

  • New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Observed

Conflicts

No material conflict detected in the available evidence.

Timeline

  1. First reported

Market move following event

Market reaction is not yet available for this asset and time window.

Score explanation

Confidence · formula confidence-2.1.0
Source trust80
Independent corroboration51
Primary evidence35
Claim consistency82
Extraction confidence82
Attribution quality90
Impact · formula impact-2.1.0
Event magnitude62
Market relevance74
Entity significance42
Market breadth45
Novelty68
Urgency55
Ranking · formula rank-1.0.0
Confidence factor0.8425
Freshness factor0.9897
Breaking bonus0