WordPress released security patches in version 7.1.1 to fix a core flaw that could let a logged-in administrator be tricked into automatically installing a theme from WordPress.org through a crafted link. Researchers at pwn.ai named the attack chain Click2Shell and showed it could be paired with a separate theme flaw, such as one in Mobile Repair Zone, to achieve code execution on the server. #WordPress #Click2Shell #pwnai #MobileRepairZone
Keypoints
- WordPress 7.1.1 patches a core vulnerability that can auto-install an inactive theme from WordPress.org.
- pwn.ai named the attack chain Click2Shell.
- The flaw requires a logged-in administrator to open a specially crafted link.
- A second weakness in the Mobile Repair Zone theme could turn the forced install into server-side code execution.
- WordPress says supported branches back to 4.7 are fixed, and no public exploitation has been reported.
Read More: https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html