THEMETASEC

Cybersecurity News, Aggregated

WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover

Security Affairs · 1 hour ago Vuln

WordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a username that doesn’t exist, and WordPress echoes it back with a tiny formatting flaw baked into […]

Read full story at Security Affairs →