WordPress has patched a vulnerability researchers call Click2Shell. According to SecurityWeek, the issue could let an attacker install themes and achieve remote code execution.
Site owners should apply the relevant WordPress update promptly, confirm that administrative access is protected with strong credentials and MFA where available, and review recently installed themes and administrator accounts for unexpected changes.
Source: SecurityWeek.
