WordPress "Click2Shell" flaw allows PHP code execution on servers
Security researchers have published technical details for a new WordPress Core vulnerability dubbed "Click2Shell." The flaw allows an unauthenticated attacker to force-install any theme from the official WordPress.org catalog and execute arbitrary PHP code on the target server.
The attack requires a logged-in site administrator to visit a specially crafted link, for example through a phishing message. The vulnerability affects WordPress Core version 7.1.0 and earlier; it was fixed with the release of version 7.1.1.
Exploiting the bug could allow attackers to modify or delete files, access user data and the wp-config.php file containing database credentials, and create rogue administrator accounts.
Administrators are strongly advised to update WordPress to the latest version as soon as possible.
Source: wordpress.org
23 September 2026