Download Privacy Needle App

Type to search

Cybersecurity

WordPress Patches ‘Click2Shell’ Vulnerability to Prevent Remote Code Execution

Share

WordPress has released security patches to address a vulnerability dubbed ‘Click2Shell’, which could allow attackers to achieve remote code execution (RCE) on a website.

The flaw was discovered and reported by researchers at pwn.ai. It enables an unauthenticated attacker to use specially crafted URLs to automatically install and preview inactive themes on a WordPress site.

Technical Exploitation Risk

While an inactive theme might appear to pose a low risk, pwn.ai found that the vulnerability can be leveraged to execute malicious code. The issue arises because a value in the WordPress theme-preview URL is interpreted differently by the themes API and the JavaScript running in an administrator’s browser. The API reduces the value to an ordinary theme slug, but the browser retains the original punctuation and places it inside a jQuery selector.

This discrepancy allows attackers to force the installation of a selected theme from the official WordPress.org catalog without the administrator’s knowledge or consent. Researchers identified over 40 third-party themes that could be abused to execute PHP code while they are inactive. Because WordPress loads PHP code during the Customizer preview—even when a different theme is currently active—an attacker can use an unprotected installer to point to a crafted plugin package for execution under the WordPress server account.

Crucially, the attack does not require a WordPress account. According to pwn.ai, a single visit from a logged-in administrator to a malicious URL is sufficient for an attacker to gain control of the site. The exploit is difficult to detect because the site’s primary theme remains active throughout the process.

Remediation and Patching

The ‘Click2Shell’ vulnerability does not currently have a CVE identifier. WordPress addressed the flaw, along with 10 other security vulnerabilities, in version 7.1.1 of the content management system.

Security updates have also been released for older iterations of the software, dating back to WordPress 4.7. Site administrators are advised to update their installations to the latest available version immediately to mitigate the risk of remote code execution.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.