← Back to feed
general SC Media

WordPress 'XSS2Shell' flaw allows admin takeover and remote code execution

SC Media WordPress

The XSS2Shell flaw begins with a specially crafted username that bypasses WordPress's initial HTML tag sanitization.

T1190
Read the full story SC Media →

Related Coverage

general US sanctions Iranian cyber actors as UK discloses power plant attack The Record · Aug 24 general SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules Cyberscoop · Aug 24 general AWS patches flaw in 7 SDKs SC Media · Aug 24