WordPress core security release (7.1.1)
Security Patch Release
Summary
Hide ▲
Show ▼
WordPress 7.1.1 shipped a security release that patches new WordPress core vulnerabilities and covers supported branches back to 4.7. The update closes a flaw that could let a logged-in administrator trigger a theme install from WordPress.org by opening a crafted link. WordPress told site owners to update right away, and the release is already available for affected branches. WordPress said there is no sign of real-world abuse.
Related Happenings
WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)
Security Patch Release
H score9
First: 15.09.2026 17:45
Last: 15.09.2026 17:45
Sources 1
About this happening:
The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upl...
WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)
Security Patch ReleaseAbout this happening: The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upl...
ThemeFusion security patch release for CVE-2026-18431
Security Patch Release
H score43
First: 27.08.2026 00:33
Last: 27.08.2026 00:33
Sources 1
About this happening:
ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
ThemeFusion security patch release for CVE-2026-18431
Security Patch ReleaseAbout this happening: ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
Elementor Pro 4.2.2 security update for CVE-2026-32475
Security Patch Release
H score27
First: 20.08.2026 09:04
Last: 20.08.2026 09:04
Sources 1
About this happening:
Elementor Pro released version 4.2.2 on August 19, 2026 to fix CVE-2026-32475, a critical unauthenticated file-upload RCE in the plugin’s Forms module File U...
Elementor Pro 4.2.2 security update for CVE-2026-32475
Security Patch ReleaseAbout this happening: Elementor Pro released version 4.2.2 on August 19, 2026 to fix CVE-2026-32475, a critical unauthenticated file-upload RCE in the plugin’s Forms module File U...
WordPress security patch release for CVE-2026-64638
Security Patch Release
H score34
First: 07.08.2026 15:56
Last: 07.08.2026 15:56
Sources 1
About this happening:
WordPress 7.0.3 shipped a security fix for CVE-2026-64638, and the release was backported through the 4.7 branch. WordPress urged operators to update immediately a...
WordPress security patch release for CVE-2026-64638
Security Patch ReleaseAbout this happening: WordPress 7.0.3 shipped a security fix for CVE-2026-64638, and the release was backported through the 4.7 branch. WordPress urged operators to update immediately a...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch Release
H score32
First: 27.07.2026 17:40
Last: 27.07.2026 17:40
Sources 1
About this happening:
vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch ReleaseAbout this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
Timeline
-
18.09.2026 19:56 2 articles · 2h ago
WordPress ships 7.1.1 security release for Click2Shell
Mitigation Patch UpdateWordPress shipped 7.1.1 on September 17, 2026 to fix a core flaw that could let a logged-in administrator open a crafted link and automatically install a theme from WordPress.org without clicking Install; the security release covered supported branches back to 4.7.
Show sources
- New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution — thehackernews.com — 18.09.2026 19:56
- New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution — thehackernews.com — 18.09.2026 19:56
-
18.09.2026 19:56 1 articles · 2h ago
pwn.ai details Click2Shell chain to server-side code execution
Initial Disclosurepwn.ai called the attack chain Click2Shell and showed that the WordPress core flaw could be combined with a separate weakness in the Mobile Repair Zone theme to run attacker code on the server; WordPress described the issue as specially crafted URLs that can automatically install and preview an inactive theme from WordPress.org.
Show sources
- New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution — thehackernews.com — 18.09.2026 19:56