Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Addresses Critical Security Flaw ‘Click2Shell’

WordPress Addresses Critical Security Flaw ‘Click2Shell’

Posted on September 22, 2026 By CWS

WordPress has recently rolled out updates to address 11 vulnerabilities, including a critical flaw known as ‘Click2Shell’ that could potentially lead to remote code execution (RCE). This vulnerability, though currently lacking a CVE identifier, has been detailed in a recent advisory from WordPress.

Exploitation Pathway of Click2Shell

The Click2Shell vulnerability can be exploited through specially crafted URLs designed to automatically install and preview inactive themes within WordPress. Despite appearing innocuous, this flaw poses significant risks, as noted by cybersecurity firm pwn.ai, responsible for identifying and reporting the issue.

The vulnerability arises because a value embedded in the WordPress theme-preview URL is processed differently by the theme API compared to the JavaScript in an administrator’s browser. According to pwn.ai, this discrepancy leads the API to convert the value to a standard theme slug, while the browser retains the original syntax within a jQuery selector.

Potential Risks and Exploits

This discrepancy permits unauthorized attackers to install a theme of their choosing on an administrator’s site without consent. These themes, fetched from the official WordPress.org repository, can then be exploited for RCE. pwn.ai discovered that over 40 third-party themes could be misused for executing PHP code, even while inactive.

During the Customizer preview process, WordPress loads PHP code from inactive themes, potentially allowing attackers to utilize vulnerable installers to direct the system towards a malicious plugin package. This exploit requires no attacker account; a single visit from a logged-in user is sufficient to compromise the site.

WordPress’s Response and Future Updates

To mitigate these risks, WordPress released patches in version 7.1.1, addressing Click2Shell and 10 other vulnerabilities. The update extends back to WordPress versions 4.7, ensuring broader protection. As a token of appreciation, WordPress awarded pwn.ai with a $300 bug bounty, the maximum reward offered.

The recent updates are crucial for maintaining website security, especially as administrators may overlook suspicious activities due to the continued operation of the main theme during exploitation attempts.

Website owners and administrators are strongly advised to update their WordPress installations immediately to safeguard against these vulnerabilities and prevent potential security breaches.

Security Week News Tags:administrator risk, Click2Shell, CMS, content management system, Cybersecurity, PHP execution, RCE, Security, software update, theme vulnerability, Vulnerability, website security, WordPress, WordPress patch

Post navigation

Previous Post: Zyxel and Veeam Vulnerabilities Under Active Exploit
Next Post: Windows Vulnerability Exploited Through Malicious DLLs

Related Posts

Zero-Day Flaw in Palo Alto Firewalls Potentially Linked to China Zero-Day Flaw in Palo Alto Firewalls Potentially Linked to China Security Week News
US Seizes .8 Million From Zeppelin Ransomware Operator US Seizes $2.8 Million From Zeppelin Ransomware Operator Security Week News
Optimizely Suffers Cyberattack Through Vishing Tactics Optimizely Suffers Cyberattack Through Vishing Tactics Security Week News
Critical Security Flaw in GitLab Resolved Critical Security Flaw in GitLab Resolved Security Week News
Honoring Our Veteran Readers: Thank You for Your Service Honoring Our Veteran Readers: Thank You for Your Service Security Week News
Grafana Suffers Data Breach, Codebase Stolen Grafana Suffers Data Breach, Codebase Stolen Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Use Fake Websites for Chrome and Windows Exploits
  • OT Network Segmentation Lacks Full Isolation: Study
  • DORA’s Impact on SOC Visibility: Key Insights
  • Critical Vulnerability Found in D-Link Router
  • Malicious npm Package Conceals Code in Runtime

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Use Fake Websites for Chrome and Windows Exploits
  • OT Network Segmentation Lacks Full Isolation: Study
  • DORA’s Impact on SOC Visibility: Key Insights
  • Critical Vulnerability Found in D-Link Router
  • Malicious npm Package Conceals Code in Runtime

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark