conv.

All stories
SecurityActive today · day 4

WordPress Click2Shell Flaw Lets Admins Unwittingly Install Malicious Themes

A critical vulnerability in WordPress core chains theme installation to code execution when logged-in administrators click a crafted link.

What to know

  • WordPress patched a critical CVSS 9.6 vulnerability (Click2Shell) on September 17 that forces theme installation via malicious links opened by logged-in admins, with no separate CVE assigned yet.
  • The attack exploits divergent URL parsing between WordPress.org's directory and the admin interface, automatically triggering the Install button without user clicks.
  • The flaw chains with weaknesses in certain themes (like Mobile Repair Zone) to achieve remote code execution; WordPress core alone only installs real themes.
  • No real-world attacks have been documented; immediate patching to 7.1.1 or equivalent is advised, with no alternative workaround available.

pwn.ai Security research firmWordPress Software vendor

WordPress Click2Shell Flaw Lets Admins Unwittingly Install Malicious Themes
github.com

How it unfolded 3 developments, newest first · click a bar or a number to jump articlesposts

Peak 6 pieces in one hour at Sep 20, 6 AM; 50 pieces over 4 days (15 articles · 15 posts · 20 comments) Sep 20, 6 AM — 6 pieces · 6 articles — Google News 6Sep 20, 7 AM — quietSep 20, 8 AM — quietSep 20, 9 AM — quietSep 20, 10 AM — quietSep 20, 11 AM — quietSep 20, 12 PM — quietSep 20, 1 PM — quietSep 20, 2 PM — quietSep 20, 3 PM — quietSep 20, 4 PM — quietSep 20, 5 PM — quietSep 20, 6 PM — quietSep 20, 7 PM — quietSep 20, 8 PM — quietSep 20, 9 PM — quietSep 20, 10 PM — quietSep 20, 11 PM — quietSep 21, 12 AM — quietSep 21, 1 AM — quietSep 21, 2 AM — quietSep 21, 3 AM — quietSep 21, 4 AM — quietSep 21, 5 AM — quietSep 21, 6 AM — quietSep 21, 7 AM — 1 piece · 1 post — Mastodon 1Sep 21, 8 AM — quietSep 21, 9 AM — quietSep 21, 10 AM — quietSep 21, 11 AM — quietSep 21, 12 PM — quietSep 21, 1 PM — 1 piece · 1 post — Mastodon 1Sep 21, 2 PM — quietSep 21, 3 PM — quietSep 21, 4 PM — quietSep 21, 5 PM — quietSep 21, 6 PM — quietSep 21, 7 PM — quietSep 21, 8 PM — quietSep 21, 9 PM — quietSep 21, 10 PM — quietSep 21, 11 PM — quietSep 22, 12 AM — 1 piece · 1 post — Mastodon 1Sep 22, 1 AM — quietSep 22, 2 AM — quietSep 22, 3 AM — 1 piece · 1 post — Mastodon 1Sep 22, 4 AM — quietSep 22, 5 AM — 2 pieces · 1 article · 1 post — Mastodon 1, Newswires 1Sep 22, 6 AM — quietSep 22, 7 AM — quietSep 22, 8 AM — quietSep 22, 9 AM — quietSep 22, 10 AM — quietSep 22, 11 AM — 2 pieces · 1 article · 1 post — Hacker News 1, Newswires 1Sep 22, 12 PM — 3 pieces · 1 post · 2 comments — Hacker News 2, X 1Sep 22, 1 PM — 6 pieces · 1 article · 5 comments — Hacker News 5, Google News 1Sep 22, 2 PM — 4 pieces · 4 comments — Hacker News 4Sep 22, 3 PM — quietSep 22, 4 PM — 3 pieces · 2 posts · 1 comment — Mastodon 2, Hacker News 1Sep 22, 5 PM — 1 piece · 1 comment — Hacker News 1Sep 22, 6 PM — 1 piece · 1 comment — Hacker News 1Sep 22, 7 PM — quietSep 22, 8 PM — quietSep 22, 9 PM — quietSep 22, 10 PM — quietSep 22, 11 PM — 1 piece · 1 comment — Hacker News 1Yesterday, 12 AM — 1 piece · 1 post — Mastodon 1Yesterday, 1 AM — quietYesterday, 2 AM — quietYesterday, 3 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 4 AM — 4 pieces · 4 articles — Google News 4Yesterday, 5 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 6 AM — 1 piece · 1 article — Mastodon 1Yesterday, 7 AM — 2 pieces · 1 post · 1 comment — Hacker News 1, Mastodon 1Yesterday, 8 AM — 1 piece · 1 post — Mastodon 1Yesterday, 9 AM — quietYesterday, 10 AM — 1 piece · 1 comment — Hacker News 1Yesterday, 11 AM — quietYesterday, 12 PM — quietYesterday, 1 PM — 2 pieces · 2 posts — Mastodon 2Yesterday, 2 PM — quietYesterday, 3 PM — quietYesterday, 4 PM — quietYesterday, 5 PM — 1 piece · 1 comment — Hacker News 1Yesterday, 6 PM — quietYesterday, 7 PM — quietYesterday, 8 PM — quietYesterday, 9 PM — quietYesterday, 10 PM — 1 piece · 1 post — Hacker News 1Yesterday, 11 PM — quietToday, 12 AM — quietToday, 1 AM — quietToday, 2 AM — 1 piece · 1 article — Newswires 1 123
Sep 21Sep 22yesterdaynow · 3:52 AM ET
  1. 3

    Public exploit code released for Click2Shell vulnerability

    Technical details and proof-of-concept exploits for Click2Shell were published, making the attack methodology publicly available. The vulnerability is classified as a cross-site request forgery (CSRF) flaw in WordPress Core.

    • All WordPress users need to update their WordPress installations immediately 💯 There is a 9.2 CVE that discloses a remote code execution vulnerability that affects versions all the way back to 2016 😬 Here's the official notice

      @jaydrogersX1d ago11▲view on X ↗
    2 more of the top 3 · 28 posts in this stretch
    • campuscodi@mastodon.social

      WordPress patched an unauth path traversal yesterday: https:// github.com/WordPress/wordpress -develop/security/advisories/GHSA-7hp8-65ch-5whp https:// wordpress.org/news/2026/09/wor dpress-7-1-2-release/ This is now being exploited, a few hours later: https:// x.com/ethicalhack3r/status/210 2747373873004680

      campuscodi@mastodon.socialMastodon18h ago1▲view on Mastodon ↗
    • This kind of bug pathology is incredibly common in all sorts of programs and is the reason (disclaimer: self-plug) I wrote libpathrs[1].Sadly, almost all language standard libraries do not provide the right abstractions for dealing with files (the primary focus is on global paths as opposed to scoped paths or file descriptors / file handles) so…

      cypharHacker News1d agoview on Hacker News ↗
    all of them →
  2. 2

    pwn.ai releases full technical analysis of the attack chain

    Security firm pwn.ai published detailed technical analysis showing how the core flaw works: WordPress.org's directory parser and the admin browser's DOM parser read URLs differently, allowing attackers to inject characters that trigger the Install button. The firm demonstrated chaining the forced install with a weakness in the Mobile Repair Zone theme to achieve code execution.

    “The Core bug does not accept an arbitrary theme ZIP by itself.”
    — pwn.ai
  3. 1

    Click2Shell vulnerability details published

    Security coverage emerged across multiple outlets detailing the Click2Shell flaw, describing how crafted links can install themes without clicks and chain to code execution. The vulnerability affects WordPress versions 6.0 through those released before the fix.

    1. first by BleepingComputer, 1d ago · also The Hacker News

      1 more headline
    2. first by heise online, 22h ago · also SecurityWeek

      1 more headline
    3 more claims →
  4. background

    WordPress releases 7.1.1 patch for Click2Shell vulnerability — WordPress released version 7.1.1 as a security update addressing a critical flaw in its core software that allows forced theme installation. The patch was distributed to supported branches back to version 4.7, with automatic updates rolling out to affected sites.

Also covered reported alongside — the timeline has no entry for these yet

  1. first by Help Net Security, 22h ago · also SecurityWeek

    1 more headline

and 1 smaller piece

What people are saying 21 voices from 2 sites · best of 28 · verbatim