Skip to content
New Click2Shell Vulnerability in WordPress Enables Remote Code Execution

New Click2Shell Vulnerability in WordPress Enables Remote Code Execution

First seen 18 Sep 2026, 19:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 21:24 UTC
  • Click2Shell allows theme installation without user interaction.
  • Chaining with a theme flaw can lead to remote code execution.
  • WordPress 7.1.1 patches this critical vulnerability.

On September 17, 2026, WordPress released version 7.1.1, addressing a critical vulnerability dubbed Click2Shell. This flaw allows an attacker to force the installation of a theme from WordPress.org by exploiting specially crafted URLs opened by a logged-in administrator. The vulnerability can be chained with a separate flaw in the installed theme to execute arbitrary PHP code on the server. The affected versions include WordPress 6.0 and later. While the core flaw alone has a CVSS score of 7.1, the full exploit chain is rated critical at 9.6. No CVE identifier has been assigned yet, but WordPress plans to issue one soon. The vulnerability affects approximately 500 million websites powered by WordPress. There are currently no reports of active exploitation in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-17
WordPress 7.1.1 released
This version includes security fixes, notably addressing the Click2Shell vulnerability.
pwn.ai
2026-09-17
Click2Shell vulnerability disclosed
The flaw allows an attacker to install themes via crafted URLs, potentially leading to code execution.
Thehackernews
Recent
No active exploitation reported
As of the latest updates, there are no indications that the vulnerability has been exploited in the wild.
Thehackernews

More articles in this cluster (2)