WordPress Multiple Vulnerabilities
Release Date: 22 Sep 2026
Multiple vulnerabilities were identified in WordPress. A
remote attacker could exploit some of these vulnerabilities to trigger
cross-site scripting, security restriction bypass, sensitive information
disclosure, remote code execution and data manipulation on the targeted system.
Note:
A proof-of-concept exploit have been published for a new
WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell'.
It is a pre-authenticated remote code execution chain that allows an attacker
to install any theme in the official WordPress.org catalog and run an arbitrary
PHP file. It should be noted that although the attacker does not need to
authenticate, the Click2Shell exploit requires a site administrator who is
already logged in to visit a specially crafted URL. Hence, the risk level is
rated as High Risk.
Impact
- Remote
Code Execution
- Information
Disclosure
- Cross-Site
Scripting
- Data
Manipulation
- Security
Restriction Bypass
System / Technologies affected
- WordPress
4.7
- WordPress
4.8
- WordPress
4.9
- WordPress
5.0
- WordPress
5.1
- WordPress
5.2
- WordPress
5.3
- WordPress
5.4
- WordPress
5.5
- WordPress
5.6
- WordPress
5.7
- WordPress
5.8
- WordPress
5.9
- WordPress
6.0
- WordPress
6.1
- WordPress
6.2
- WordPress
6.3
- WordPress
6.4
- WordPress
6.5
- WordPress
6.6
- WordPress
6.7
- WordPress
6.8
- WordPress
6.9
- WordPress
7.0
Please refer to the link below:
https://wordpress.org/documentation/wordpress-version/version-7-1-1/
Solutions
Before installation of the software, please visit the
vendor web-site for more details.
Apply fixes issued by the vendor:
https://wordpress.org/documentation/wordpress-version/version-7-1-1/
Vulnerability Identifier
Note: No CVE information is available for this
vulnerability
Source
Related Link
- https://wordpress.org/documentation/wordpress-version/version-7-1-1/
- https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/
沒有留言:
發佈留言