started · updated
WordPress releases security updates to patch critical Click2Shell vulnerability
WordPress has released security updates to address critical vulnerabilities, most notably a flaw dubbed “Click2Shell.” Discovered by Paulos Yibelo of pwn.ai, the vulnerability allows attackers to execute remote PHP code on a server.
The Click2Shell exploit functions by manipulating theme-preview URLs to trick the WordPress administration panel into automatically installing an attacker-selected theme. While the attacker does not need a WordPress account, the exploit requires a logged-in administrator to click a specially crafted link. By chaining this with vulnerabilities in specific themes, such as Mobile Repair Zone 2.5.4, attackers can achieve remote code execution.
In response to these and other security threats, the WordPress team released version 7.1.1 on September 17, which patched 11 vulnerabilities. Additionally, version 7.1.2 was issued as a dedicated security release to address a critical path traversal vulnerability that could also allow remote code execution. Security experts urge all administrators to update their installations immediately to prevent unauthorized access and the creation of rogue administrator accounts.
Entities
Mobile Repair Zone · Patchstack · Paulos Yibelo · WordPress · pwn.ai
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] The Click2Shell vulnerability exploits a discrepancy in how WordPress handles theme slugs in preview URLs. cyberinsider.com · www.blogspan.net
- [○ 1 SOURCE] Attackers can achieve remote code execution by chaining the Click2Shell flaw with vulnerabilities in specific themes, such as Mobile Repair Zone 2.5.4. cyberinsider.com
- [● 2 SOURCES] Paulos Yibelo of pwn.ai discovered the Click2Shell vulnerability and reported it on August 22, 2026. cyberinsider.com · www.blogspan.net
- [● 2 SOURCES] The attack requires a logged-in administrator to click a specially crafted link but does not require the attacker to have an account. cyberinsider.com · www.blogspan.net
- [○ 1 SOURCE] WordPress released version 7.1.2 as a dedicated security release to fix a critical path traversal vulnerability. wpde.org
- [● 2 SOURCES] WordPress released version 7.1.1 on September 17 to address 11 vulnerabilities. cyberinsider.com · www.blogspan.net
- [○ 1 SOURCE] Exploits of WordPress vulnerabilities have been observed creating unauthorized hidden administrator accounts. www.singaporebestwebdesign.com