chiprook
← Security
SecuritySeptember 27, 2026, 13:20

WordPress Click2Shell: 7.9M Indexed Assets and What They Mean

On September 21, 2026, researchers disclosed an unauthenticated RCE chain in WordPress Core: a crafted link makes a logged-in admin's browser auto-install a catalog theme whose unprotected AJAX handler executes attacker PHP. WordPress fixed it in 7.1.1 via changeset 63664; no CVE exists and no in-the-wild exploitation was reported. A ZoomEye query for app="WordPress" returned 7,945,496 assets, which is not a count of vulnerable hosts.

WordPress Click2Shell: 7.9M Indexed Assets and What They Mean
#WordPress#ZoomEye
Read next
Security

WordPress Click2Shell flaw lets hackers run PHP on the server

Security

New WordPress Click2Shell flaw forces theme installs, can chain to code execution

Security

Exposed Router Management: 8.09 Million RouterOS Assets and the 9,560 That Still Answer on SSH

Security

161,764 Assets on Port 102: Sizing the Industrial Control Surface That AA26-231A Described