chiprook
← Security
SecurityOctober 7, 2026, 08:40

WordPress Click2Shell: unauthenticated RCE, fixed in 7.1.1

On September 21, 2026, researchers disclosed Click2Shell, an unauthenticated remote code execution chain in WordPress Core. A single visit by a logged-in administrator to a crafted link is enough: the browser installs a catalog theme on its own and its unprotected AJAX endpoint executes attacker-controlled PHP. WordPress fixed the core parser flaw in 7.1.1; no CVE has been assigned and no exploitation in the wild was confirmed.

WordPress Click2Shell: unauthenticated RCE, fixed in 7.1.1
#WordPress#ZoomEye
Read next
Security

Click2Shell: WordPress parser discrepancy led to RCE

Security

WordPress Click2Shell: 7.9M Indexed Assets and What They Mean

Security

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites

Security

WordPress Click2Shell flaw lets hackers run PHP on the server