WordPress Click2Shell Flaw Exposes RCE Risk Across Millions of Sites
A vulnerability dubbed Click2Shell, disclosed on September 21, 2026, revealed an unauthenticated remote code execution chain in WordPress Core that tricks a logged-in administrator into visiting a crafted URL, which then silently installs a malicious theme and executes attacker-controlled PHP. WordPress addressed the flaw in version 7.1.1 via changeset 63664, though no CVE has been assigned and no active exploitation in the wild has been reported. A ZoomEye query run on September 22, 2026 returned nearly 7.95 million WordPress assets globally, though researchers caution this figure represents exposure scope, not confirmed compromised hosts. The attack has two layers: a core parser flaw affecting all versions before 7.1.1, and a secondary stage exploiting unprotected AJAX endpoints found in over 40 catalog themes, including Mobile Repair Zone 2.5.4. Because the chain depends on social engineering an administrator to click a link, site owners are urged to patch to 7.1.1 and audit installed themes rather than treat the asset count as a breach tally.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in