Loading video...
Video Failed to Load
So... we decided to hack WordPress Core, AGAIN! 🔥 ⛓️ Click2Shell is a one-click unauthenticated remote command execution chain (Preauth RCE) affecting every WordPress website. Wordpress rolled out a fix yesterday! The story about how one preview link made WordPress click Install, load an inactive theme's PHP, and hand... show more
108,578 views • 5 days ago •via X (Twitter)
14 Comments

👏👏

Incredible stuff, unauthenticated RCE on wordpress is massive, thanks for sharing the breakdown with the community

Damn... only 300. Great find and chaining!!

⚡️⚡️

Do we get a poc?

Yes it's in the blog.

mb bruh was in a rush this morning haha

🙌🙌

was the 300$ bounty a typo ? well if its not thats crazy

Wow👏

GAD I am getting sick of updating WP. i am starting to replace them with something that is not swiss cheese.

One-click preauth RCE via a preview link is nasty. Fix shipped, but the interesting part for hunts is how many sites still expose that preview path. you seeing more Click2Shell hits on managed WP hosts or self-hosted installs?

not critical need admin to click the link

oh… please let me know the CVE ID.
