WordPress Multiple Vulnerabilities

WordPress Multiple Vulnerabilities

WordPress Multiple Vulnerabilities
Release Date:
22 Sep 2026

672
Views

RISK: High Risk

High Risk

TYPE: Servers – Internet App Servers

TYPE: Internet App Servers

Multiple vulnerabilities were identified in WordPress. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, security restriction bypass, sensitive information disclosure, remote code execution and data manipulation on the targeted system

Note:

A proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed ‘Click2Shell’. It is a pre-authenticated remote code execution chain that allows an attacker to install any theme in the official WordPress.org catalog and run an arbitrary PHP file. It should be noted that although the attacker does not need to authenticate, the Click2Shell exploit requires a site administrator who is already logged in to visit a specially crafted URL. Hence, the risk level is rated as High Risk.

Impact

  • Remote Code Execution
  • Information Disclosure
  • Cross-Site Scripting
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • WordPress 4.7
  • WordPress 4.8
  • WordPress 4.9
  • WordPress 5.0
  • WordPress 5.1
  • WordPress 5.2
  • WordPress 5.3
  • WordPress 5.4
  • WordPress 5.5
  • WordPress 5.6
  • WordPress 5.7
  • WordPress 5.8
  • WordPress 5.9
  • WordPress 6.0
  • WordPress 6.1
  • WordPress 6.2
  • WordPress 6.3
  • WordPress 6.4
  • WordPress 6.5
  • WordPress 6.6
  • WordPress 6.7
  • WordPress 6.8
  • WordPress 6.9
  • WordPress 7.0

Please refer to the link below:

https://wordpress.org/documentation/wordpress-version/version-7-1-1/

Solutions

Before installation of the software, please visit the vendor web-site for more details

 

Apply fixes issued by the vendor:

 

https://wordpress.org/documentation/wordpress-version/version-7-1-1/

Vulnerability Identifier

Note: No CVE information is available for this vulnerability

Source

Related Link

WordPressInformation DisclosureRemote Code ExecutionInformation DisclosureProof of ConceptCross Site ScriptingData ManipulationSecurity Restriction Bypass

Vous souhaitez apprendre cela de manière pratique ?

Rejoindre Justfine Infotech and build real digital skills in AI, automation, web development, digital marketing, office productivity, e-commerce, freelancing and cybersecurity.

Programmes disponibles :
6 semaines Certificat • 3 Months Professional Certificate • 6 Months Diploma • Full Professional Diploma

WhatsApp :
+229 01 57 57 99 15
+229 01 66 68 11 60

Inscrivez-vous dès maintenant

Source: www.hkcert.org

Laisser un commentaire

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont indiqués avec *

Retour en haut