Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Addresses Critical Security Flaw ‘Click2Shell’

WordPress Addresses Critical Security Flaw ‘Click2Shell’

Posted on September 22, 2026 By CWS

WordPress has recently rolled out updates to address 11 vulnerabilities, including a critical flaw known as ‘Click2Shell’ that could potentially lead to remote code execution (RCE). This vulnerability, though currently lacking a CVE identifier, has been detailed in a recent advisory from WordPress.

Exploitation Pathway of Click2Shell

The Click2Shell vulnerability can be exploited through specially crafted URLs designed to automatically install and preview inactive themes within WordPress. Despite appearing innocuous, this flaw poses significant risks, as noted by cybersecurity firm pwn.ai, responsible for identifying and reporting the issue.

The vulnerability arises because a value embedded in the WordPress theme-preview URL is processed differently by the theme API compared to the JavaScript in an administrator’s browser. According to pwn.ai, this discrepancy leads the API to convert the value to a standard theme slug, while the browser retains the original syntax within a jQuery selector.

Potential Risks and Exploits

This discrepancy permits unauthorized attackers to install a theme of their choosing on an administrator’s site without consent. These themes, fetched from the official WordPress.org repository, can then be exploited for RCE. pwn.ai discovered that over 40 third-party themes could be misused for executing PHP code, even while inactive.

During the Customizer preview process, WordPress loads PHP code from inactive themes, potentially allowing attackers to utilize vulnerable installers to direct the system towards a malicious plugin package. This exploit requires no attacker account; a single visit from a logged-in user is sufficient to compromise the site.

WordPress’s Response and Future Updates

To mitigate these risks, WordPress released patches in version 7.1.1, addressing Click2Shell and 10 other vulnerabilities. The update extends back to WordPress versions 4.7, ensuring broader protection. As a token of appreciation, WordPress awarded pwn.ai with a $300 bug bounty, the maximum reward offered.

The recent updates are crucial for maintaining website security, especially as administrators may overlook suspicious activities due to the continued operation of the main theme during exploitation attempts.

Website owners and administrators are strongly advised to update their WordPress installations immediately to safeguard against these vulnerabilities and prevent potential security breaches.

Security Week News Tags:administrator risk, Click2Shell, CMS, content management system, Cybersecurity, PHP execution, RCE, Security, software update, theme vulnerability, Vulnerability, website security, WordPress, WordPress patch

Post navigation

Previous Post: Zyxel and Veeam Vulnerabilities Under Active Exploit
Next Post: Windows Vulnerability Exploited Through Malicious DLLs

Related Posts

Google Project Zero Tackles Upstream Patch Gap With New Policy Google Project Zero Tackles Upstream Patch Gap With New Policy Security Week News
Ox Security Launches AI Agent That Auto-Generates Code to Fix Vulnerabilities Ox Security Launches AI Agent That Auto-Generates Code to Fix Vulnerabilities Security Week News
OpenAI Introduces Bug Bounty for AI Safety Risks OpenAI Introduces Bug Bounty for AI Safety Risks Security Week News
In Other News: ATM Jackpotting, WhatsApp-NSO Lawsuit Continues, CISA Hiring In Other News: ATM Jackpotting, WhatsApp-NSO Lawsuit Continues, CISA Hiring Security Week News
CISA Updates Guidance on Patching Cisco Devices Targeted in China-Linked Attacks CISA Updates Guidance on Patching Cisco Devices Targeted in China-Linked Attacks Security Week News
Motors Theme Vulnerability Exploited to Hack WordPress Websites Motors Theme Vulnerability Exploited to Hack WordPress Websites Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerability Found in D-Link Router
  • Malicious npm Package Conceals Code in Runtime
  • Windows Vulnerability Exploited Through Malicious DLLs
  • WordPress Addresses Critical Security Flaw ‘Click2Shell’
  • Zyxel and Veeam Vulnerabilities Under Active Exploit

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerability Found in D-Link Router
  • Malicious npm Package Conceals Code in Runtime
  • Windows Vulnerability Exploited Through Malicious DLLs
  • WordPress Addresses Critical Security Flaw ‘Click2Shell’
  • Zyxel and Veeam Vulnerabilities Under Active Exploit

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark