New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
AI Summary
WordPress patched a vulnerability dubbed Click2Shell, which allows a specially crafted URL to force the installation of a theme from the WordPress.org directory when clicked by a logged-in administrator, without requiring additional interaction. While the core flaw alone only installs a legitimate theme, it can be chained with a vulnerability in the installed theme to achieve remote code execution. The attack exploits inconsistent parsing of URL parameters between WordPress.org and the administrator's browser, leading to unintended automatic clicks on the Install button. The full exploit chain was demonstrated using the 'Mobile Repair Zone' theme, which contains a handler that downloads and executes arbitrary code without authentication.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | Mobile Repair Zone | Details → |