Skip to main content
See every side of every news story
Published loading...Updated

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

Summary by The Hacker News
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only
DisclaimerThis story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.

7 Articles

It is enough that a connected WordPress administrator opens an trapped link so that installs a theme of the official directory chosen by the attacker. If this theme is poorly protected, the attacker can then execute code on the server. The WordPress team has fixed this Click2Shell flaw in version 7.1.1, published on September 17.

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • There is no tracked Bias information for the sources covering this story.

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Hacker News broke the news on Friday, September 18, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal