pwn.ai New Click2Shell Vulnerability in WordPress Enables Remote Code Execution
Article Content
- •Click2Shell allows theme installation without user interaction.
- •Chaining with a theme flaw can lead to remote code execution.
- •WordPress 7.1.1 patches this critical vulnerability.
On September 17, 2026, WordPress released version 7.1.1, addressing a critical vulnerability dubbed Click2Shell. This flaw allows an attacker to force the installation of a theme from WordPress.org by exploiting specially crafted URLs opened by a logged-in administrator. The vulnerability can be chained with a separate flaw in the installed theme to execute arbitrary PHP code on the server. The affected versions include WordPress 6.0 and later. While the core flaw alone has a CVSS score of 7.1, the full exploit chain is rated critical at 9.6. No CVE identifier has been assigned yet, but WordPress plans to issue one soon. The vulnerability affects approximately 500 million websites powered by WordPress. There are currently no reports of active exploitation in the wild.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…