これはClick2Shellとは別の問題で、未ログインの第三者が細工したpagenameを送るとテーマの構造など条件次第でテーマ外のPHPファイルを読み込ませられます。
7.1系は7.1.2、旧系列は対応する修正版を確認してください。
https://chunlog.jp/wordpress-7-1-2-cve-2026-87902/?utm_source=bluesky&utm_medium=social&utm_campaign=post
#WordPress #セキュリティ
これはClick2Shellとは別の問題で、未ログインの第三者が細工したpagenameを送るとテーマの構造など条件次第でテーマ外のPHPファイルを読み込ませられます。
7.1系は7.1.2、旧系列は対応する修正版を確認してください。
https://chunlog.jp/wordpress-7-1-2-cve-2026-87902/?utm_source=bluesky&utm_medium=social&utm_campaign=post
#WordPress #セキュリティ
https://chunlog.jp/wordpress-click2shell/?utm_source=bluesky&utm_medium=social&utm_campaign=post
#WordPress #Click2Shell
https://chunlog.jp/wordpress-click2shell/?utm_source=bluesky&utm_medium=social&utm_campaign=post
#WordPress #Click2Shell
new from WordPress
📰 Source: Tux Machines
🔗 Link: https://tuxmachines.org/n/2026/09/23/WordPress_7_1_2_Release_Patches_Click2Shell_Vulnerability.shtml
new from WordPress
📰 Source: Tux Machines
🔗 Link: https://tuxmachines.org/n/2026/09/23/WordPress_7_1_2_Release_Patches_Click2Shell_Vulnerability.shtml
rocket-boys.co.jp/security-mea...
#セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース #脆弱性
rocket-boys.co.jp/security-mea...
#セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース #脆弱性
CVE-2026-87902 is unauth LFI in core template resolution. Patchstack saw probes the same day.
Update to 7.1.2 or your backport. Hunt logs for odd pagename + page_id.
Already patched? Drop a ✅. Agency life? Pass it to your clients.
CVE-2026-87902 is unauth LFI in core template resolution. Patchstack saw probes the same day.
Update to 7.1.2 or your backport. Hunt logs for odd pagename + page_id.
Already patched? Drop a ✅. Agency life? Pass it to your clients.
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]
#hackernews #news
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]
#hackernews #news
Vulnerabilidad "Click2Shell" en WordPress fuerza la instalación de temas y puede encadenarse para lograr la ejecución de código
Leer Más / Read More...
Vulnerabilidad "Click2Shell" en WordPress fuerza la instalación de temas y puede encadenarse para lograr la ejecución de código
Leer Más / Read More...
https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/
#cybersecurity
https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/
#cybersecurity
Un clic sur un lien piégé qui peut coûter cher si on est connecté en tant qu'admin à son #WordPress.
Plus d'infos par ici :
- www.it-connect.fr/wordpress-cl...
Un clic sur un lien piégé qui peut coûter cher si on est connecté en tant qu'admin à son #WordPress.
Plus d'infos par ici :
- www.it-connect.fr/wordpress-cl...
🌐 spoofguard.io/blog/en/bran...
#CyberSecurity #BrandProtection #Click2Shell #Phishing #ThreatIntel #SpoofGuard
Try it for FREE. 🆓
🌐 spoofguard.io/blog/en/bran...
#CyberSecurity #BrandProtection #Click2Shell #Phishing #ThreatIntel #SpoofGuard
Try it for FREE. 🆓
Agency checklist:
1) Confirm every install is on 7.1.1 or your branch’s security backport
2) Check inactive themes you did not expect
3) Tighten comment moderation
Agency checklist:
1) Confirm every install is on 7.1.1 or your branch’s security backport
2) Check inactive themes you did not expect
3) Tighten comment moderation
WordPress 7.1.1 shipped on September 17, 2026 carrying eleven security fixes, seventeen core bug fixes and…
http://digitalmatters.me/security/wordpress-7-1-1-click2shell/
#Cyber_Security #Security #WordPress
WordPress 7.1.1 shipped on September 17, 2026 carrying eleven security fixes, seventeen core bug fixes and…
http://digitalmatters.me/security/wordpress-7-1-1-click2shell/
#Cyber_Security #Security #WordPress