WordPress Patches ‘Click2Shell’ Vulnerability
WordPress patched a vulnerability called Click2Shell that allowed attackers to automatically install and preview inactive themes via specially crafted URLs. This flaw could lead to remote code execution (RCE) by abusing how theme slugs are interpreted differently by the themes API and JavaScript in an administrator's browser. Attackers could force installation of attacker-selected themes fetched from the official WordPress.org catalog without administrator consent. Some inactive third-party themes could be exploited for PHP code execution during the Customizer preview, enabling attackers to execute code under the WordPress server account without needing an attacker WordPress account. The vulnerability was fixed in WordPress version 7.1.1 and backported to versions as early as 4.7.
AI Analysis
Technical Summary
The Click2Shell vulnerability in WordPress arises from inconsistent interpretation of a value in the theme-preview URL by the themes API and the JavaScript running in an administrator's browser. The API reduces the value to a standard theme slug, while the browser retains original punctuation and uses it in a jQuery selector. This discrepancy allows an unauthenticated attacker to install an attacker-chosen inactive theme from the official WordPress.org catalog without administrator knowledge. Although inactive themes normally pose limited risk, over 40 third-party themes were identified that could be abused for PHP code execution during the Customizer preview, which loads PHP code of inactive themes. This enables remote code execution under the WordPress server account with just a single visit from a logged-in user, without requiring an attacker WordPress account. WordPress released patches in version 7.1.1 and backported fixes to versions back to 4.7. The vulnerability was responsibly disclosed by pwn.ai, who also published technical details and proof-of-concept code.
Potential Impact
Successful exploitation allows an unauthenticated attacker to force installation of an attacker-selected inactive theme, which can be leveraged to execute arbitrary PHP code on the WordPress server during theme preview. This leads to remote code execution with the privileges of the WordPress server process. The attack requires only a single visit from a logged-in user and does not require the attacker to have a WordPress account. The administrator may not notice the exploit since the active theme remains unchanged during the attack.
Mitigation Recommendations
WordPress has released an official patch for the Click2Shell vulnerability in version 7.1.1 and backported fixes to all supported versions back to 4.7. Site administrators should upgrade to WordPress 7.1.1 or later, or apply the corresponding security updates for their WordPress version. No additional mitigation actions are required beyond applying the official patches.
WordPress Patches ‘Click2Shell’ Vulnerability
Description
WordPress patched a vulnerability called Click2Shell that allowed attackers to automatically install and preview inactive themes via specially crafted URLs. This flaw could lead to remote code execution (RCE) by abusing how theme slugs are interpreted differently by the themes API and JavaScript in an administrator's browser. Attackers could force installation of attacker-selected themes fetched from the official WordPress.org catalog without administrator consent. Some inactive third-party themes could be exploited for PHP code execution during the Customizer preview, enabling attackers to execute code under the WordPress server account without needing an attacker WordPress account. The vulnerability was fixed in WordPress version 7.1.1 and backported to versions as early as 4.7.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Click2Shell vulnerability in WordPress arises from inconsistent interpretation of a value in the theme-preview URL by the themes API and the JavaScript running in an administrator's browser. The API reduces the value to a standard theme slug, while the browser retains original punctuation and uses it in a jQuery selector. This discrepancy allows an unauthenticated attacker to install an attacker-chosen inactive theme from the official WordPress.org catalog without administrator knowledge. Although inactive themes normally pose limited risk, over 40 third-party themes were identified that could be abused for PHP code execution during the Customizer preview, which loads PHP code of inactive themes. This enables remote code execution under the WordPress server account with just a single visit from a logged-in user, without requiring an attacker WordPress account. WordPress released patches in version 7.1.1 and backported fixes to versions back to 4.7. The vulnerability was responsibly disclosed by pwn.ai, who also published technical details and proof-of-concept code.
Potential Impact
Successful exploitation allows an unauthenticated attacker to force installation of an attacker-selected inactive theme, which can be leveraged to execute arbitrary PHP code on the WordPress server during theme preview. This leads to remote code execution with the privileges of the WordPress server process. The attack requires only a single visit from a logged-in user and does not require the attacker to have a WordPress account. The administrator may not notice the exploit since the active theme remains unchanged during the attack.
Mitigation Recommendations
WordPress has released an official patch for the Click2Shell vulnerability in version 7.1.1 and backported fixes to all supported versions back to 4.7. Site administrators should upgrade to WordPress 7.1.1 or later, or apply the corresponding security updates for their WordPress version. No additional mitigation actions are required beyond applying the official patches.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/wordpress-patches-click2shell-vulnerability/","fetched":true,"fetchedAt":"2026-09-22T10:32:45.972Z","wordCount":1033}
Threat ID: 6ab2594df7a7c541060adeaa
Added to database: 09/22/2026, 10:32:45 UTC
Last enriched: 09/22/2026, 10:32:52 UTC
Last updated: 09/22/2026, 19:02:17 UTC
Views: 36
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.