WordPress에서 새로운 Click2Shell flaw를 패치하여 코드 실행 가능성을 차단했습니다.
WordPress는 관리자가 클릭 없이 테마를 설치할 수 있는 취약점에 대한 패치를 발표했습니다. 이 취약점은 pwn.ai의 연구자들에 의해 발견되었으며, 'Click2Shell'이라는 공격 체인으로 알려져 있습니다. 관리자가 악성 링크를 클릭할 경우 시스템에 해로운 코드를 실행할 수 있는 상황이 발생할 수 있었습니다. 해당 패치를 통해 사용자는 이제 보다 안전하게 WordPress를 사용할 수 있게 되었습니다.
WordPress patches a Click2Shell flaw that allows theme installs without clicks, preventing potential code execution.
WordPress has released patches to address a vulnerability that could allow an administrator to install a theme without clicking. This flaw, reported by researchers at pwn.ai, is part of an attack chain known as Click2Shell. If an admin were to open a crafted link, it could lead to executing harmful code on the system. The patch enhances the security of WordPress, allowing users to operate with greater safety.