Skip to content
Click2Shell Exploit Targets WordPress Pre-Authentication Flaw

Click2Shell Exploit Targets WordPress Pre-Authentication Flaw

First seen 19 Sep 2026, 10:17 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 20, 2026 at 10:11 UTC
  • Click2Shell is a critical remote code execution vulnerability in WordPress.
  • The vulnerability affects versions prior to WordPress 7.1.1, released on September 17, 2026.
  • Proof-of-concept scripts are available, but testing should only be done in controlled environments.

The Click2Shell exploit, a pre-authentication remote code execution vulnerability in WordPress, was publicly disclosed by the pwn.ai research team on September 18, 2026. This vulnerability affects WordPress installations prior to version 7.1.1, which was released on September 17, 2026, to address the issue. The exploit allows attackers to execute arbitrary code without authentication, posing a significant risk to affected systems. Users are urged to verify their installations and apply the patch if they are running vulnerable versions. The proof-of-concept scripts for the exploit have been made available for lab testing only, emphasizing the need for responsible use. Organizations should ensure that their WordPress installations are updated to mitigate this risk. The scope of impact could be widespread given the popularity of WordPress as a content management system.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-17
WordPress 7.1.1 released
WordPress released version 7.1.1 to patch the Click2Shell vulnerability.
Sploitus
2026-09-18
Click2Shell vulnerability disclosed
The pwn.ai research team publicly disclosed the Click2Shell exploit affecting WordPress.
Sploitus
2026-09-19
Exploit scripts made public
Python proof-of-concept scripts for Click2Shell were released for lab use only.
Sploitus

More articles in this cluster (2)