WordPress core Click2Shell security flaw
Vulnerability
Summary
Hide ▲
Show ▼
WordPress core now has a fixed Click2Shell flaw that can make a logged-in administrator install an attacker-chosen theme from WordPress.org, creating a path to server compromise when chained with a second bug. WordPress shipped the fix in 7.1.1 on September 17, 2026, and says there is no sign of real-world abuse. The flaw affects the core link-handling flow and can trigger theme installation without an explicit Install click. Researchers showed that the forced install can be combined with a separate theme weakness to reach code execution.
Related Happenings
WooCommerce Wholesale Lead Capture actively exploited arbitrary file-upload vulnerability (CVE-2026-27540)
Vulnerability
H score16
First: 15.09.2026 17:45
Last: 15.09.2026 17:45
Sources 1
About this happening:
CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin is being actively exploited, putting version 2.0.3.1 and older at risk of PHP webshell...
WooCommerce Wholesale Lead Capture actively exploited arbitrary file-upload vulnerability (CVE-2026-27540)
VulnerabilityAbout this happening: CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin is being actively exploited, putting version 2.0.3.1 and older at risk of PHP webshell...
WordPress login screen pre-auth reflected XSS (CVE-2026-64638)
Vulnerability
H score24
First: 07.08.2026 15:56
Last: 07.08.2026 15:56
Sources 1
About this happening:
WordPress patched CVE-2026-64638, a pre-auth reflected XSS in the login screen that affects every version of the CMS. The flaw can be chained under additional...
WordPress login screen pre-auth reflected XSS (CVE-2026-64638)
VulnerabilityAbout this happening: WordPress patched CVE-2026-64638, a pre-auth reflected XSS in the login screen that affects every version of the CMS. The flaw can be chained under additional...
Timeline
-
18.09.2026 19:56 1 articles · 2h ago
WordPress ships WordPress 7.1.1 to close Click2Shell
Mitigation Patch UpdateWordPress shipped a security fix in WordPress 7.1.1 on September 17, closing the Click2Shell core flaw across supported branches back to 4.7 after researchers showed a crafted link opened by a logged-in administrator could force an inactive theme install from WordPress.org.
Show sources
- New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution — thehackernews.com — 18.09.2026 19:56
-
18.09.2026 19:56 2 articles · 2h ago
pwn.ai details Click2Shell in WordPress core
Initial Disclosurepwn.ai names Click2Shell as a WordPress core flaw where a specially crafted URL opened by a logged-in administrator can automatically install and preview an inactive theme from WordPress.org without clicking Install; WordPress says no CVE identifier has been assigned yet.
Show sources
- New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution — thehackernews.com — 18.09.2026 19:56
- New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution — thehackernews.com — 18.09.2026 19:56