WordPress Multiple Vulnerabilities

Imported from official source

Announcement

Multiple vulnerabilities were identified in WordPress. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, security restriction bypass, sensitive information disclosure, remote code execution and data manipulation on the targeted system.

A proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell'. It is a pre-authenticated remote code execution chain that allows an attacker to install any theme in the official WordPress.org catalog and run an arbitrary PHP file. It should be noted that although the attacker does not need to authenticate, the Click2Shell exploit requires a site administrator who is already logged in to visit a specially crafted URL. Hence, the risk level is rated as High Risk.

Before installation of the software, please visit the vendor web-site for more details.

Note: No CVE information is available for this vulnerability

This is an extract. The publication continues at the source.

Read the original at the source: https://www.hkcert.org/security-bulletin/wordpress-multiple-vulnerabilities_20260922

Officially imported this from Hong Kong Computer Emergency Response Team Coordination Centre’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Hong Kong Computer Emergency Response Team Coordination Centre — imported from official source
Official source
https://www.hkcert.org/getrss/security-bulletin RSS
Imported
October 03, 2026 20:41
Versions
1 recorded
Identity
https://www.hkcert.org/security-bulletin/wordpress-multiple-vulnerabilities_20260922

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.