
WordPress Patches Critical XSS2Shell Vulnerability Enabling Server Takeover
CybersecurityVulnerabilitiesWebSecurityHackingWordPress
The WordPress development team has patched a security vulnerability labeled XSS2Shell, which affected the login page and could enable server takeover. The flaw was described as a cross-site scripting (XSS) issue with potential for remote code execution. No specific CVE identifier, affected version range, or exact patch release date was provided in the notice. The vulnerability was addressed by the WordPress developers, though no details on exploitation in the wild were mentioned. The impact included unauthorized access and control over vulnerable WordPress servers. The original report was published by heise.de.