A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. […]
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek.
WordPress has released an emergency security update addressing a critical vulnerability in its Core software that can allow an unauthenticated attacker to load arbitrary local PHP files and, under specific server and theme conditions, achieve remote code execution. Tracked as CVE-2026-87902, the vulnerability affects WordPress releases from version 4.7.0 through 7.1.1 and carries a CVSS […]
CVE-2026-87902 in WordPress Enables Conditional RCE Security updates released for WordPress address CVE-2026-87902 , a severe unauthenticated path traversal flaw within its page-template resolution mechanism. The weaknes
The bug lets attackers automatically install and preview themes and could lead to remote code execution. The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek.
Say goodbye to buying compressed air canisters in bulk.
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed ‚Click2Shell‘ that affects the platform’s Core component. […]
Click2Shell: WordPress Flaw Enables RCE Chain Click2Shell is a vulnerability in WordPress Core that allows a logged-in administrator’s browser to be manipulated into installing and previewing a theme without explicit con