[REVISION HISTORY]
WordPress security vulnerabilities and patches
Updated 1 time since CLSTR started tracking revisions of this situation.
What changed
2026-09-22 10:48 UTC → 2026-09-22 17:24 UTC ·
added
removed
Security researchers identified critical vulnerabilities in the WordPress content management system, leading to the release of security update version 7.1.1. One major flaw, known as ‘Click2Shell’, allows for remote code execution (RCE). This vulnerability vulnerability, discovered by Paulos Yibelo of pwn.ai, exploits the theme-preview function by using specially crafted URLs to trick logged-in administrators into silently installing an inactive theme. Attackers can then chain this with a second vulnerability within a specific theme, such as ‘Mobile Repair Zone’, Zone 2.5.4’, to execute malicious code on the server. A second vulnerability, nicknamed ‘wp2shell’, enables attackers to take control of websites without a password. In observed attacks, this exploit was used to quietly create unauthorized administrator accounts on unpatched sites. The Following the initial 7.1.1 maintenance release also addresses other issues, release, which addressed 11 vulnerabilities including stored cross-site scripting (XSS), authenticated path traversal, and authorization bypasses. bypasses, the WordPress team issued version 7.1.2. This subsequent dedicated security release specifically addresses a critical path traversal vulnerability that could also facilitate remote code execution. Security experts urge all administrators to update installations immediately to prevent unauthorized access.
Versions
- 2026-09-22 17:24 UTC WordPress security vulnerabilities and patches
- 2026-09-22 10:48 UTC WordPress security vulnerabilities and patches
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.