chiprook
← Security
SecurityOctober 2, 2026, 13:20

Click2Shell: WordPress parser discrepancy led to RCE

The Click2Shell report published September 21, 2026 describes a WordPress RCE chain: the API canonicalizes a theme parameter to a slug while the browser inserts the raw value into a jQuery selector. Mobile Repair Zone 2.5.4 and over 40 other themes with an unprotected AJAX endpoint are affected; the fix is changeset 63664.

Click2Shell: WordPress parser discrepancy led to RCE
#WordPress
Read next
Security

WordPress Click2Shell: 7.9M Indexed Assets and What They Mean

Security

WordPress Click2Shell flaw lets hackers run PHP on the server

Security

New WordPress Click2Shell flaw forces theme installs, can chain to code execution

Security

WordPress Comment2Shell flaw turns anonymous comment XSS into RCE