🚨 Click2Shell: Critical WordPress RCE chain A malicious link can trigger an authenticated WordPress admin’s browser to silently install a theme, load its functions.php, abuse an insecure AJAX handler
php, abuse an insecure AJAX handler, and reach remote code execution. 1, but vulnerable third-party themes can still complete the chain.