← Back to feed
general SC Media

WordPress 'XSS2Shell' flaw allows admin takeover and remote code execution

SC Media WordPress

The XSS2Shell flaw begins with a specially crafted username that bypasses WordPress's initial HTML tag sanitization.

T1190
Read the full story SC Media →

Related Coverage

general Prismor: Open-source runtime control plane for AI agents Help Net Security · Sep 23 general Hackers Exploit Check Point 0-Day Flaw to Execute Code on Management Servers GBHackers · Sep 23 general Stealthy WordPress Malware Uses Must-Use Plugin and Ethereum EtherHiding for Persistent Backdoor Access GBHackers · Sep 23