Skip to main content

WordPress Patches ‘Click2Shell’ Vulnerability

0
Critical
Vulnerabilitywordpressremoterce
Published: 09/22/2026 (09/22/2026, 10:22:27 UTC)
Source: SecurityWeek

Description

WordPress patched a vulnerability called Click2Shell that allowed attackers to automatically install and preview inactive themes via specially crafted URLs. This flaw could lead to remote code execution (RCE) by abusing how theme slugs are interpreted differently by the themes API and JavaScript in an administrator's browser. Attackers could force installation of attacker-selected themes fetched from the official WordPress.org catalog without administrator consent. Some inactive third-party themes could be exploited for PHP code execution during the Customizer preview, enabling attackers to execute code under the WordPress server account without needing an attacker WordPress account. The vulnerability was fixed in WordPress version 7.1.1 and backported to versions as early as 4.7.

Affected software

Affected versions
>=4.7 <7.1.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/22/2026, 10:32:52 UTC

Technical Analysis

The Click2Shell vulnerability in WordPress arises from inconsistent interpretation of a value in the theme-preview URL by the themes API and the JavaScript running in an administrator's browser. The API reduces the value to a standard theme slug, while the browser retains original punctuation and uses it in a jQuery selector. This discrepancy allows an unauthenticated attacker to install an attacker-chosen inactive theme from the official WordPress.org catalog without administrator knowledge. Although inactive themes normally pose limited risk, over 40 third-party themes were identified that could be abused for PHP code execution during the Customizer preview, which loads PHP code of inactive themes. This enables remote code execution under the WordPress server account with just a single visit from a logged-in user, without requiring an attacker WordPress account. WordPress released patches in version 7.1.1 and backported fixes to versions back to 4.7. The vulnerability was responsibly disclosed by pwn.ai, who also published technical details and proof-of-concept code.

Potential Impact

Successful exploitation allows an unauthenticated attacker to force installation of an attacker-selected inactive theme, which can be leveraged to execute arbitrary PHP code on the WordPress server during theme preview. This leads to remote code execution with the privileges of the WordPress server process. The attack requires only a single visit from a logged-in user and does not require the attacker to have a WordPress account. The administrator may not notice the exploit since the active theme remains unchanged during the attack.

Mitigation Recommendations

WordPress has released an official patch for the Click2Shell vulnerability in version 7.1.1 and backported fixes to all supported versions back to 4.7. Site administrators should upgrade to WordPress 7.1.1 or later, or apply the corresponding security updates for their WordPress version. No additional mitigation actions are required beyond applying the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.95,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/wordpress-patches-click2shell-vulnerability/","fetched":true,"fetchedAt":"2026-09-22T10:32:45.972Z","wordCount":1033}

Threat ID: 6ab2594df7a7c541060adeaa

Added to database: 09/22/2026, 10:32:45 UTC

Last enriched: 09/22/2026, 10:32:52 UTC

Last updated: 09/22/2026, 19:02:17 UTC

Views: 36

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses