Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 16 sources · 4 days · First seen · Last updated
WordPress security vulnerabilities and patches
Overview
Security researchers identified critical vulnerabilities in the WordPress content management system, leading to the release of security update version 7.1.1.
One major flaw, known as ‘Click2Shell’, allows for remote code execution (RCE). This vulnerability, discovered by Paulos Yibelo of pwn.ai, exploits the theme-preview function by using specially crafted URLs to trick logged-in administrators into silently installing an inactive theme. Attackers can then chain this with a second vulnerability within a specific theme, such as ‘Mobile Repair Zone 2.5.4’, to execute malicious code on the server.
A second vulnerability, nicknamed ‘wp2shell’, enables attackers to take control of websites without a password. In observed attacks, this exploit was used to quietly create unauthorized administrator accounts on unpatched sites.
Following the initial 7.1.1 maintenance release, which addressed 11 vulnerabilities including stored cross-site scripting (XSS), authenticated path traversal, and authorization bypasses, the WordPress team issued version 7.1.2. This subsequent dedicated security release specifically addresses a critical path traversal vulnerability that could also facilitate remote code execution. Security experts urge all administrators to update installations immediately to prevent unauthorized access.
Entities
WordPress · Anthropic · WordPress.org · Mobile Repair Zone · pwn.ai
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] WordPress released version 7.1.1 on September 17 to address 11 vulnerabilities. cyberinsider.com · www.blogspan.net
- [● 2 SOURCES] Paulos Yibelo of pwn.ai discovered the Click2Shell vulnerability and reported it on August 22, 2026. cyberinsider.com · www.blogspan.net
- [● 2 SOURCES] The Click2Shell vulnerability exploits a discrepancy in how WordPress handles theme slugs in preview URLs. cyberinsider.com · www.blogspan.net
- [● 2 SOURCES] The attack requires a logged-in administrator to click a specially crafted link but does not require the attacker to have an account. cyberinsider.com · www.blogspan.net
- [○ 1 SOURCE] Attackers can achieve remote code execution by chaining the Click2Shell flaw with vulnerabilities in specific themes, such as Mobile Repair Zone 2.5.4. cyberinsider.com
- [○ 1 SOURCE] WordPress released version 7.1.2 as a dedicated security release to fix a critical path traversal vulnerability. wpde.org
- [○ 1 SOURCE] Exploits of WordPress vulnerabilities have been observed creating unauthorized hidden administrator accounts. www.singaporebestwebdesign.com
Timeline
-
1 day ago
[TECHNOLOGY] 6 sourcesWordPress releases security updates to patch critical Click2Shell vulnerabilityWordPress has issued urgent security updates, including versions 7.1.1 and 7.1.2, to patch critical vulnerabilities like “Click2Shell” that allow remote code execution via malicious links.
-
5 days ago
[TECHNOLOGY] 10 sourcesWordPress releases security update to patch Click2Shell RCE vulnerabilityWordPress released version 7.1.1 to patch the ‘Click2Shell’ vulnerability, which can lead to remote code execution via malicious theme-preview URLs.
Sources
appinn.com · blogspan.net · cyberinsider.com · cybernoz.com · es.wordpress.org · flagthis.com · it-boltwise.de · ithome.com · paraonline.com.br · reclaimhosting.com · sadio.org.ar · singaporebestwebdesign.com · turbolab.it · upday.com · wordpress.org · wpde.org
This summary has been updated 1 time: see revision history