WordPress Click2Shell: 7.9M Indexed Assets and What They Mean
On September 21, 2026, researchers disclosed an unauthenticated RCE chain in WordPress Core: a crafted link makes a logged-in admin's browser auto-install a catalog theme whose unprotected AJAX handler executes attacker PHP. WordPress fixed it in 7.1.1 via changeset 63664; no CVE exists and no in-the-wild exploitation was reported. A ZoomEye query for app="WordPress" returned 7,945,496 assets, which is not a count of vulnerable hosts.
- The chain requires a logged-in administrator to visit an attacker-chosen URL
- WordPress 7.1.1 closes the forced theme-installation stage
- The second stage abuses AJAX endpoints in Mobile Repair Zone 2.5.4 and 40+ themes
- ZoomEye: 7,945,496 WordPress assets indexed on September 22, 2026
Read next
Security