ChipokiaTech news, without the noise
← All stories

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as…

Preview courtesy of The Hacker News. The full article opens on their site.

More from The Hacker News

Top today