socradar.io 21 Sept 2026, 14:12 UTC

WordPress Click2Shell Flaw Chains With Themes to Enable PHP Execution

WordPress Click2Shell Flaw Chains With Themes to Enable PHP Execution
CyberSIXT Evidence Panel Source marked as original reporting

RESEARCHERS have disclosed “Click2Shell”, a WordPress Core vulnerability that can manipulate a logged-in administrator’s browser into installing and previewing a theme from WordPress.org after the administrator clicks a specially crafted link. The flaw stems from inconsistent handling of a URL-derived theme parameter between WordPress’s administrator-side JavaScript and Themes API.

It does not independently execute code, and does not require the attacker to have an account, but it does require administrator interaction. As of 21 September, no CVE had been assigned.

The issue is believed to affect WordPress versions before 7.1.1. WordPress released 7.1.1 and security updates for older branches on 17 September, including 7.0.5, 6.9.8, 6.8.9, 6.7.8, 6.6.8, 6.5.11, 6.4.11, 6.3.11, 6.2.12, 6.1.13 and 6.0.15. A public proof of concept from pwn.ai, published on 18 September, demonstrates forced theme installation and a possible PHP-execution chain.

In testing, researchers combined Click2Shell with a weakness in Mobile Repair Zone 2.5.4, where PHP ran during Customizer preview and an unauthenticated AJAX handler lacked capability checks and nonce validation. They said more than 40 other third-party themes have comparable flaws. Researchers rated the standalone issue CVSS 7.1 and the chain CVSS 9.3, although WordPress had not issued an official score.

There is no confirmed evidence of exploitation in the wild. Administrators should update WordPress Core, remove unnecessary themes and plugins, and review inactive themes, administrator sessions, theme-installation activity and unexpected PHP or configuration changes. Particular attention should be paid to unusual requests involving `wp-admin/theme-install.php`, Customizer activity, or `admin-ajax.php`.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline