U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog.
Unauthenticated users can run remote code, putting millions of websites at risk. Learn how to protect your site now.
The hole, which allows an unauthenticated attacker to perform remote code execution, is especially dangerous because many enterprises are not aware of all of their WordPress sites.
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.
WordPress has patched Click2Shell, that could allow an attacker to silently install a theme and execute PHP code on the targeted website.
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component ...
WordPress Click2Shell vulnerability lets attackers silently install themes on any admin’s site via a single crafted link, ...
WordPress 7.1.1 fixes Click2Shell, which can force theme installs from crafted links and was chained with a theme flaw for code execution.
The UN General Assembly gavelled open its 81st session on Tuesday at UN Headquarters as the incoming president pledged to restore public trust in the institution during a time of war, humanitarian ...
Statement of the Kingdom of the Netherlands, delivered by H.E. Mr. Lars Tummers, Ambassador, Deputy Permanent Representative, Permanent Representation of the Kingdom of the Netherlands to the United ...