WordPress Click2Shell flaw lets hackers run PHP on the server
Researcher Paulos Yibelo of pwn.ai disclosed Click2Shell, a CSRF vulnerability in WordPress Core that lets an attacker force-install any theme from the WordPress.org catalog and execute arbitrary PHP. The flaw was fixed in WordPress 7.1.1, and exploitation requires a logged-in administrator to visit a crafted URL.
- Click2Shell is a pre-auth RCE chain in WordPress Core 7.1.0 and earlier
- Fixed in WordPress 7.1.1 by escaping the theme slug in the jQuery selector
- Attack requires a logged-in admin to open a crafted link
- Full technical report and PoC exploit are public
Read next
Security