New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress released security patches in version 7.1.1 to fix a core flaw that could let a logged-in administrator be tricked into automatically installing a theme from WordPress.org through a crafted link. Researchers at pwn.ai named the attack chain Click2Shell and showed it could be paired with a separate theme flaw, such as one in Mobile Repair Zone, to achieve code execution on the server. #WordPress #Click2Shell #pwnai #MobileRepairZone

Keypoints

  • WordPress 7.1.1 patches a core vulnerability that can auto-install an inactive theme from WordPress.org.
  • pwn.ai named the attack chain Click2Shell.
  • The flaw requires a logged-in administrator to open a specially crafted link.
  • A second weakness in the Mobile Repair Zone theme could turn the forced install into server-side code execution.
  • WordPress says supported branches back to 4.7 are fixed, and no public exploitation has been reported.

Read More: https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html