WordPress Click2Shell: unauthenticated RCE, fixed in 7.1.1
On September 21, 2026, researchers disclosed Click2Shell, an unauthenticated remote code execution chain in WordPress Core. A single visit by a logged-in administrator to a crafted link is enough: the browser installs a catalog theme on its own and its unprotected AJAX endpoint executes attacker-controlled PHP. WordPress fixed the core parser flaw in 7.1.1; no CVE has been assigned and no exploitation in the wild was confirmed.
- Attack needs no WordPress account — just an admin clicking a crafted link
- Browser auto-installs a catalog theme whose AJAX endpoint runs attacker PHP
- Core flaw fixed in WordPress 7.1.1, no CVE identifier yet
- ZoomEye: 7,945,496 WordPress assets indexed as of September 22, 2026
Read next
Security