Click2Shell: WordPress parser discrepancy led to RCE
The Click2Shell report published September 21, 2026 describes a WordPress RCE chain: the API canonicalizes a theme parameter to a slug while the browser inserts the raw value into a jQuery selector. Mobile Repair Zone 2.5.4 and over 40 other themes with an unprotected AJAX endpoint are affected; the fix is changeset 63664.
- Attack requires a logged-in admin to visit a crafted link
- Affected: Mobile Repair Zone 2.5.4 and 40+ other catalog themes
- No CVE assigned yet and no in-the-wild exploitation confirmed
- Fix in changeset 63664 escapes the theme slug before jQuery
Read next
Security