chiprook
← Security
SecuritySeptember 18, 2026, 23:56

New WordPress Click2Shell flaw forces theme installs, can chain to code execution

WordPress released patches for a new set of core vulnerabilities. The Click2Shell chain allows installing a theme from the official WordPress.org directory without clicking the Install button, requiring only that an administrator opens a specially crafted link. The vulnerability can lead to arbitrary code execution.

New WordPress Click2Shell flaw forces theme installs, can chain to code execution
#WordPress
Read next
Security

Kaspersky uncovers malware campaign spread via movie torrents

Security

Z.ai silently uploaded devs' local data: 313MB and 564 upload attempts

Security

Samsung and LG to remove botnet apps from smart TV stores

Security

CrowdSec confirms source code stolen in supply chain attack