Click2Shell: How a WordPress Theme Flaw Chains Into Full Server Compromise
A specially crafted WordPress link can trick a logged-in administrator’s browser into installing an attacker-selected theme, creating a path to server-side PHP execution when...
Read Full Story →
