WordPress Click2Shell Flaw Silently Installs Themes via Crafted Admin Link

A single crafted link sent to a logged-in WordPress administrator can silently install an attacker-chosen theme on the target site - no Install button click required - and that installed theme can then be turned into a server-level foothold within seconds. WordPress patched the underlying flaw on September 17 in version 7.1.1, but public working exploit code landed on GitHub the following day, collapsing the effective patching window for self-hosted sites still running vulnerable builds.Security research firm pwn.ai, which discovered and reported the vulnerability, disclosed the full attack chain on September 18 and named it Click2Shell to describe its end goal: a single malicious link, opened by any site administrator, that ultimately delivers a remote shell on the target server.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in