A WordPress vulnerability allows attackers to force theme installation on administrator accounts through a crafted link, potentially enabling code execution via a supply chain attack vector.
Summary is Secursion's own; full text lives at the source. Attribution preserved.