The record
Written from the 1 report below. Nothing here is unsourced.
- WordPress has released a security update, version 7.1.1, to address a vulnerability that could allow an attacker to force the installation of a theme via a crafted link opened by an administrator.
- While the flaw on its own does not execute code, researchers demonstrated that it can be chained with additional vulnerabilities in specific themes to achieve remote code execution.
- The issue arises from how WordPress interprets links and processes administrative sessions.
- Users are strongly advised to update their WordPress installations immediately to mitigate this risk.
What to watch next
- Monitor for the assignment of a formal CVE identifier for this vulnerability.
- Observe if threat actors begin weaponizing the forced-install vulnerability in the wild.
- Check official security advisories for further details on affected themes used in exploit chains.
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
pwn.ai
security firm
1 quote · 1 outlet
“The Core bug does not accept an arbitrary theme ZIP by itself.”
In the article
…stays switched off, so the site's own appearance does not change and nothing looks wrong. Reaching code execution needed a second, separate flaw in the theme that was installed. As pwn.ai wrote of the core bug alone, " The Core bug does not accept an arbitrary theme ZIP by itself. " The flaw works because two parts of WordPress read the same link differently. The WordPress.org directory treats the value in the link as an ordinary theme name and returns a real theme, but the administrator's…
WordPress
1 quote · 1 outlet
“Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org.”
In the article
…own as high severity, with a CVSS score of 7.1, and the full chain to code execution as critical, at 9.6. WordPress has not published a severity rating of its own, and in its release it described the issue this way: " Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org. " No CVE identifier has been assigned yet, though pwn.ai says WordPress plans to add one. WordPress fixed the flaw in 7.1.1, part of a security release whose fixes reach supported branches back to 4.7. Its notes confirm…
Coverage1
All filed from India
Named United States · Mobile Repair Zone · Wordpress · pwn.ai
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
