Recent Vulnerability in WordPress Click2Shell Requires Theme Installations and Potentially Leads to Code Execution

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

New Security Flaw in WordPress Prompting Urgent Updates

On September 18, 2026, WordPress unveiled significant patches to rectify an array of vulnerabilities within its core software.

Notably, one flaw enables a maliciously crafted web link, if accessed by a logged-in administrator, to illicitly install a theme from the official WordPress.org directory without requiring any affirmative action such as clicking on the “Install” button.

The cybersecurity firm pwn.ai, which uncovered this critical vulnerability, has dubbed the attack sequence Click2Shell.

While this particular flaw independently installs a legitimate theme of the attacker’s choosing, pwn.ai demonstrated that it can be maliciously combined with another existing vulnerability within a theme, thus enabling the execution of the attacker’s own code on the server.

The remedy was released on September 17, coinciding with WordPress version 7.1.1. Given the nature of this security update, WordPress strongly recommends that users effectuate the update without delay, despite current indications showing that this vulnerability has not yet been exploited in actual attack scenarios.

Once installed, the theme remains inactive, which means there are no visible alterations to the site’s design. However, executing code would necessitate an additional flaw within the installed theme.

As pwn.ai noted regarding the core vulnerability alone, “The Core bug does not accept an arbitrary theme ZIP by itself.”

Intriguingly, the vulnerability arises from disparate interpretations of the same URL by distinct components within WordPress.

The WordPress.org directory recognizes the value in the link as a standard theme name and consequently returns a legitimate theme.

Conversely, the administrator’s browser retains the original text, including punctuation, within a coding context designed to select an item on the page.

Any extraneous characters introduced by the attacker to the URL facilitate an automatic click on the Install button, executed by WordPress’s internal script.

Given that the administrator is already logged in, their session inadvertently provides both the necessary permissions and the security token required for the installation, negating the need for the attacker to supply either element.

It’s noteworthy that an installed theme may not remain dormant. During the creation of a preview within WordPress’s Customizer tool, the PHP code of the theme can be executed even prior to activation of the theme itself.

The specific theme exploited by pwn.ai, named Mobile Repair Zone, contained an additional vulnerability: a background handler that accepts a web address from the incoming request, downloads a package, and executes its code without verifying the visitor’s permissions or a corresponding security token. When chained to the forced installation, this handler subsequently executes the attacker’s code on the server.

The researchers assigned a high severity rating to the forced-install flaw, awarding it a CVSS score of 7.1, while the complete chain facilitating code execution attained a critical score of 9.6.

To date, WordPress has not publicly assigned a severity rating, instead characterizing the issue succinctly: “Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org.” A CVE identifier has yet to be allocated, although pwn.ai anticipates that WordPress will assign one soon.

WordPress successfully addressed this vulnerability in version 7.1.1, which is part of a broader security release that rectifies issues across supported versions back to 4.7.

The release notes confirm the identified flaw persists from version 6.0 and affects all preceding releases up to the fix.

Site owners are strongly urged to upgrade to version 7.1.1 or the appropriate update corresponding to their current branch. Systems configured for automatic updates should receive the patch seamlessly.

For those unable to immediately implement the update, it is crucial to note that neither WordPress nor pwn.ai provided a distinct workaround, and the attack necessitates a logged-in administrator to engage the attacker’s link.

Updating the WordPress core effectively neutralizes the demonstrated threat, regardless of the active theme on a site.

This incident marks not the first encounter for pwn.ai with vulnerabilities in WordPress core. In August, a similar flaw discovered in the login screen was also rectified, which likewise posed potential code execution risks. Once again, WordPress’s characterization of the risk fell short of the researchers’ detailed analysis.

Additionally, a prior WordPress core vulnerability announced in July, termed wp2shell, remains unrelated to the work of pwn.ai.

A glass wall with a red CISA logo in front of server racks in a data center.

This particular flaw exploited does not require any login or user interaction; it has consequently drawn attention from the U.S. cybersecurity agency CISA, which has flagged it as actively exploited in real-world attacks—contrasting starkly with the currently dormant Click2Shell threat.

Source link: Thehackernews.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading