Find notable cyber news and cases, enriched with sources, timelines, and signals.

WordPress core Click2Shell security flaw

Vulnerability
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

WordPress core now has a fixed Click2Shell flaw that can make a logged-in administrator install an attacker-chosen theme from WordPress.org, creating a path to server compromise when chained with a second bug. WordPress shipped the fix in 7.1.1 on September 17, 2026, and says there is no sign of real-world abuse. The flaw affects the core link-handling flow and can trigger theme installation without an explicit Install click. Researchers showed that the forced install can be combined with a separate theme weakness to reach code execution.

Related Happenings

WooCommerce Wholesale Lead Capture actively exploited arbitrary file-upload vulnerability (CVE-2026-27540)

Vulnerability
H score16 First: 15.09.2026 17:45 Last: 15.09.2026 17:45 Sources 1

About this happening: CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin is being actively exploited, putting version 2.0.3.1 and older at risk of PHP webshell...

WordPress login screen pre-auth reflected XSS (CVE-2026-64638)

Vulnerability
H score24 First: 07.08.2026 15:56 Last: 07.08.2026 15:56 Sources 1

About this happening: WordPress patched CVE-2026-64638, a pre-auth reflected XSS in the login screen that affects every version of the CMS. The flaw can be chained under additional...

Timeline

  1. 18.09.2026 19:56 1 articles · 2h ago

    WordPress ships WordPress 7.1.1 to close Click2Shell

    Mitigation Patch Update

    WordPress shipped a security fix in WordPress 7.1.1 on September 17, closing the Click2Shell core flaw across supported branches back to 4.7 after researchers showed a crafted link opened by a logged-in administrator could force an inactive theme install from WordPress.org.

    Show sources
  2. 18.09.2026 19:56 2 articles · 2h ago

    pwn.ai details Click2Shell in WordPress core

    Initial Disclosure

    pwn.ai names Click2Shell as a WordPress core flaw where a specially crafted URL opened by a logged-in administrator can automatically install and preview an inactive theme from WordPress.org without clicking Install; WordPress says no CVE identifier has been assigned yet.

    Show sources