🚨 Click2Shell: Critical WordPress RCE chain A malicious link can trigger an authenticated WordPress admin’s browser to silently install a theme, load its functions.php, abuse an insecure AJAX handler

php, abuse an insecure AJAX handler, and reach remote code execution. 1, but vulnerable third-party themes can still complete the chain.

4 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

🚨 Click2Shell: Critical WordPress RCE chain A malicious link can trigger an authenticated WordPress admin’s browser to silently install a theme, load its functions.php, abuse an insecure AJAX handler

mastodon:infosec-exchangeother10d ago kagi ↗

🚨 Click2Shell: Critical WordPress RCE chain A malicious link can trigger an authenticated WordPress admin’s browser to silently install a theme, load its functions.php, abuse an insecure AJAX handler, and reach remote code execution. The Core flaw is patched in WordPress 7.1.1, but vulnerable third-party themes can still complete the chain. Full technical breakdown + PoC analysis: https:// thecyb

# WordPress admin clicks a link. WordPress clicks Install. “Click2Shell” abuses the admin’s logged-in session to silently install an attacker-chosen theme. Chain it with a vulnerable theme: server-sid

mastodon:infosec-exchangeother10d ago kagi ↗

# WordPress admin clicks a link. WordPress clicks Install. “Click2Shell” abuses the admin’s logged-in session to silently install an attacker-chosen theme. Chain it with a vulnerable theme: server-side PHP execution. Patch WordPress core to 7.1.1 now! 👇 https:// thehackernews.com/2026/09/new- wordpress-click2shell-flaw-forces.html

Click2Shell Exploit Chain Grants RCE on WordPress via Malicious Links WordPress 7.1.1 patches 11 security flaws, including the "Click2Shell" exploit chain that allows unauthenticated attackers to gain

mastodon:infosec-exchangeother8d ago kagi ↗

Click2Shell Exploit Chain Grants RCE on WordPress via Malicious Links WordPress 7.1.1 patches 11 security flaws, including the "Click2Shell" exploit chain that allows unauthenticated attackers to gain remote code execution by tricking an administrator into clicking a malicious link. **Update WordPress to version 7.1.1 right away. The exploit chain exposes your WordPress when an admin simply clicks