WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover
VulnWordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a username that doesn’t exist, and WordPress echoes it back with a tiny formatting flaw baked into […]
Read full story at Security Affairs →