π€ WordPress 'Click2Shell' (no CVE): pre-auth RCE chain via CSRF in Core. A crafted theme-preview URL installs a theme from the WordPress.org catalog β even inactive, it executes PHP during Customizer
π€ WordPress 'Click2Shell' (no CVE): pre-auth RCE chain via CSRF in Core. A crafted theme-preview URL installs a theme from the WordPress.org catalog β even inactive, it executes PHP during Customizer preview. PoC published; patched in 7.1.1. Found by pwn.ai's Paulos Yibelo. π https://www. bleepingcomputer.com/news/secu rity/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/ # Wor