Wednesday, 07 October 2026

WordPress "Click2Shell" flaw allows PHP code execution on servers

Security researchers have published technical details for a new WordPress Core vulnerability dubbed "Click2Shell." The flaw allows an unauthenticated attacker to force-install any theme from the official WordPress.org catalog and execute arbitrary PHP code on the target server.

The attack requires a logged-in site administrator to visit a specially crafted link, for example through a phishing message. The vulnerability affects WordPress Core version 7.1.0 and earlier; it was fixed with the release of version 7.1.1.

Exploiting the bug could allow attackers to modify or delete files, access user data and the wp-config.php file containing database credentials, and create rogue administrator accounts.

Administrators are strongly advised to update WordPress to the latest version as soon as possible.

Source: wordpress.org

23 September 2026

-
52