← Back to feed
general SC Media

WordPress 'XSS2Shell' flaw allows admin takeover and remote code execution

SC Media • • WordPress

The XSS2Shell flaw begins with a specially crafted username that bypasses WordPress's initial HTML tag sanitization.

T1190
Read the full story SC Media →

Related Coverage

general Co-creator of Empire Market dark web marketplace given 40-year sentence The Record · Oct 10 general Citrix Urges Immediate Patching of Critical NetScaler Vulnerability SecurityWeek · Oct 9 general MATCHBOIL Malware Adds Sandbox Checks, .NET Reactor Obfuscation and Persistent C2 GBHackers · Oct 9