importantSYS.SOURCE: The Hacker News• 2026-09-18T22:26:19+05:30
WordPress Click2Shell Vulnerability Enables Forced Theme Installation and Potential Code Execution
A newly discovered WordPress vulnerability, dubbed Click2Shell, allows attackers to force theme installations without user interaction by exploiting a crafted URL. When combined with a separate theme vulnerability, it enables code execution on the server, though no active exploitation has been reported.
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.
The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only
*** END OF TRANSMISSION ***