roots/wordpress is vulnerable to Remote Code Execution (RCE)
93
Critical Risk
A URL-derived theme slug flows unescaped into a jQuery selector in WordPress Core's wp-admin/js/theme.js. A specially crafted theme-install.php?theme= URL closes the attribute selector and reaches the genuine Install control, so WordPress's own admin JavaScript automatically installs and previews an attacker-selected WordPress.org catalog theme after a logged-in administrator merely visits the link (no click on Install/Activate). Chained with a vulnerable installed-but-inactive theme loaded via the Customizer preview (for example mobile-repair-zone 2.5.4, among 40+ affected themes), an attacker achieves unauthenticated remote code execution as the WordPress server account ("Click2Shell"). Fixed in changeset 63664 by escaping the slug with $.escapeSelector and constraining the match to a div.theme card.
You are affected if you are using a version that falls within the vulnerable range and a logged-in administrator can be induced to visit an attacker-controlled link targeting theme-install.php. Reaching code execution additionally requires a separately vulnerable theme to be installable/present.
roots/wordpress is vulnerable to Remote Code Execution (RCE) in versions 7.1 - 7.1, 7.0 - 7.0.4, 6.9 - 6.9.7, 6.8 - 6.8.8, 6.7 - 6.7.7, 6.6 - 6.6.7, 6.5 - 6.5.10, 6.4 - 6.4.10, 6.3 - 6.3.10, 6.2 - 6.2.11, 6.1 - 6.1.12, 6.0 - 6.0.14, 5.9 - 5.9.16, 5.8 - 5.8.15, 5.7 - 5.7.17, 5.6 - 5.6.19, 5.5 - 5.5.20 and 0.0.1 - 5.4.21.
Upgrade the roots/wordpress library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.