security1 publisher
Click2Shell runs attacker PHP on WordPress servers after a single administrator click
Paulos Yibelo of pwn.ai reported the Core flaw on August 22 and WordPress fixed it in 7.1.1 last week. The full proof-of-concept is now public, and the chain needs no attacker account, only an administrator who opens a link.
Publishers:bleepingcomputer.com
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives70
- Confidence58