Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Patch Addresses Click2Shell Vulnerability

WordPress Patch Addresses Click2Shell Vulnerability

Posted on September 18, 2026 By CWS

WordPress has issued a patch to repair vulnerabilities in its core software, including a significant flaw known as Click2Shell. This vulnerability allows a crafted web link to install a theme from WordPress.org without the need for user interaction, provided it is opened by a logged-in administrator.

Understanding the Click2Shell Flaw

The flaw, discovered by security researchers at pwn.ai, can install a legitimate theme chosen by an attacker. However, when combined with another vulnerability within that theme, it could potentially allow the execution of malicious code on the server. WordPress released a fix on September 17, as part of version 7.1.1, urging users to update immediately. There is no evidence of this flaw being exploited in real-world scenarios yet.

Technical Details and Potential Impact

The vulnerability arises because two components of WordPress interpret the same link differently. While the WordPress.org directory sees it as a regular theme name, the administrator’s browser retains the original format, which could trigger an unwanted installation process. The attack leverages the fact that a logged-in administrator’s session provides the necessary permissions for installation without further authorization.

Though the theme remains inactive post-installation, WordPress’s Customizer tool can still load its PHP code. This was exemplified by pwn.ai using a theme with a secondary flaw that executed code from an external source without proper authorization checks.

Recommendations and Future Outlook

The Click2Shell vulnerability has been rated with a high severity score on its own and as critical when the full exploit chain is considered. WordPress has not yet published its own severity assessment, but it has acknowledged the risk, explaining the issue as URLs capable of installing and previewing inactive themes. Users are encouraged to install version 7.1.1 or the equivalent update for their branch to mitigate this vulnerability.

For those unable to update immediately, it is important to note that the attack requires an administrator to open the malicious link. As such, no workaround has been suggested by WordPress or pwn.ai. Updating the WordPress core is the recommended solution to prevent potential exploitation.

Recent Security Challenges in WordPress

This is not the first time WordPress has had to address significant security vulnerabilities. In August, a similar flaw was patched, which involved the login screen and was also linked to potential code execution. Another separate vulnerability, identified in July, called wp2shell, does not require login credentials or user interaction and has been recognized by U.S. cybersecurity authorities as actively exploited.

Staying updated with the latest patches and understanding the nature of these vulnerabilities is crucial for WordPress site owners to maintain robust security and protect against potential threats.

The Hacker News Tags:Administrator, Click2Shell, code execution, CVE, Cybersecurity, PHP code, pwn.ai, security flaw, security patch, theme install, Update, Vulnerability, web security, WordPress, WordPress.org

Post navigation

Previous Post: Feral Wolf Ransomware Exploits Exposed Business Systems
Next Post: Settra Ransomware Threatens Windows Networks

Related Posts

Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise The Hacker News
PhantomRaven Malware Found in 126 npm Packages Stealing GitHub Tokens From Devs PhantomRaven Malware Found in 126 npm Packages Stealing GitHub Tokens From Devs The Hacker News
Optimize Security by Testing Attack Chains Holistically Optimize Security by Testing Attack Chains Holistically The Hacker News
Critical Check Point VPN Vulnerability Exploited Critical Check Point VPN Vulnerability Exploited The Hacker News
U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack The Hacker News
Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Lead New Wave of Ransomware Threats
  • Security Flaw in AI Coding Agents Allows Malicious Plugin Swaps
  • Settra Ransomware Threatens Windows Networks
  • WordPress Patch Addresses Click2Shell Vulnerability
  • Feral Wolf Ransomware Exploits Exposed Business Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Lead New Wave of Ransomware Threats
  • Security Flaw in AI Coding Agents Allows Malicious Plugin Swaps
  • Settra Ransomware Threatens Windows Networks
  • WordPress Patch Addresses Click2Shell Vulnerability
  • Feral Wolf Ransomware Exploits Exposed Business Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark