bleeping-computer · Crawled Sep 21, 2026

WordPress Click2Shell flaw lets hackers execute PHP on the server

Read original article ↗

AI Summary

A pre-authenticated remote code execution vulnerability in WordPress Core, dubbed 'Click2Shell', allows attackers to force-install a theme from the WordPress.org catalog and execute arbitrary PHP code via a Customizer preview. The exploit chain does not require attacker authentication but relies on a logged-in administrator visiting a crafted URL. The vulnerability was patched in WordPress 7.1.1, which fixes improper escaping of the theme slug in jQuery selectors and restricts selector scope to legitimate theme cards. Successful exploitation could lead to full server compromise, including access to database credentials and creation of rogue admin accounts.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.