# WordPress security vulnerabilities and patches

> Live situation record from CLSTR: https://clstr.news/situations/wordpress-security-vulnerabilities-and-patches
> Updated: 2026-09-21T16:09:19.000Z. Sources: 16. Developments: 2.

Security researchers identified critical vulnerabilities in the WordPress content management system, leading to the release of security update version 7.1.1.

One major flaw, known as ‘Click2Shell’, allows for remote code execution (RCE). This vulnerability, discovered by Paulos Yibelo of pwn.ai, exploits the theme-preview function by using specially crafted URLs to trick logged-in administrators into silently installing an inactive theme. Attackers can then chain this with a second vulnerability within a specific theme, such as ‘Mobile Repair Zone 2.5.4’, to execute malicious code on the server.

A second vulnerability, nicknamed ‘wp2shell’, enables attackers to take control of websites without a password. In observed attacks, this exploit was used to quietly create unauthorized administrator accounts on unpatched sites. 

Following the initial 7.1.1 maintenance release, which addressed 11 vulnerabilities including stored cross-site scripting (XSS), authenticated path traversal, and authorization bypasses, the WordPress team issued version 7.1.2. This subsequent dedicated security release specifically addresses a critical path traversal vulnerability that could also facilitate remote code execution. Security experts urge all administrators to update installations immediately to prevent unauthorized access.

## Claims

- WordPress released version 7.1.1 on September 17 to address 11 vulnerabilities. (corroborated by 2 sources)
- Paulos Yibelo of pwn.ai discovered the Click2Shell vulnerability and reported it on August 22, 2026. (corroborated by 2 sources)
- The Click2Shell vulnerability exploits a discrepancy in how WordPress handles theme slugs in preview URLs. (corroborated by 2 sources)
- The attack requires a logged-in administrator to click a specially crafted link but does not require the attacker to have an account. (corroborated by 2 sources)
- Attackers can achieve remote code execution by chaining the Click2Shell flaw with vulnerabilities in specific themes, such as Mobile Repair Zone 2.5.4. (single source)
- WordPress released version 7.1.2 as a dedicated security release to fix a critical path traversal vulnerability. (single source)
- Exploits of WordPress vulnerabilities have been observed creating unauthorized hidden administrator accounts. (single source)

## Timeline

### 2026-09-21: WordPress releases security updates to patch critical Click2Shell vulnerability

WordPress has issued urgent security updates, including versions 7.1.1 and 7.1.2, to patch critical vulnerabilities like “Click2Shell” that allow remote code execution via malicious links.

6 sources. https://clstr.news/cluster/wordpress-patches-critical-vulnerabilities-including-click2shell-and-wp2shell

### 2026-09-17: WordPress releases security update to patch Click2Shell RCE vulnerability

WordPress released version 7.1.1 to patch the ‘Click2Shell’ vulnerability, which can lead to remote code execution via malicious theme-preview URLs.

10 sources. https://clstr.news/cluster/wordpress-releases-711-security-and-maintenance-update

---
Cite as: WordPress security vulnerabilities and patches. CLSTR, https://clstr.news/situations/wordpress-security-vulnerabilities-and-patches
