< Back to all clusters
[TECHNOLOGY] · 10 sources

started · updated

WordPress releases security update to patch Click2Shell RCE vulnerability

WordPress has released security update version 7.1.1 to address a critical vulnerability known as ‘Click2Shell’. Discovered by researchers from pwn. ai, the exploit chain allows attackers to achieve remote code execution (RCE) by targeting a weakness in the theme-preview function.

The vulnerability works by using specially crafted URLs that trick a logged-in administrator into silently installing and previewing an inactive theme from the official WordPress.org directory. While the theme remains inactive and does not immediately change the site's appearance, the installation can be chained with a second vulnerability within the chosen theme to execute malicious code on the server.

In addition to Click2Shell, the 7.1.1 maintenance release includes 11 security fixes, 17 core bug fixes, and 19 Block Editor fixes. Other addressed issues include stored cross-site scripting (XSS), authenticated path traversal, and authorization bypasses. Administrators of WordPress sites running version 4.7 or higher are urged to update immediately to protect against these threats.

Entities

Anthropic · WordPress · WordPress.org · pwn. ai