Threat update
A newly disclosed vulnerability in WordPress Core, nicknamed Click2Shell, allows an attacker to take control of a WordPress website if a logged-in administrator simply opens a specially crafted link. No further clicks, prompts, or approvals are needed. WordPress fixed the issue in version 7.1.1 and backported the fix to every supported branch back to 4.7. Because proof-of-concept code is now public, any organization running WordPress should confirm its sites are updated today.
