WordPress Pre-Authentication Remote Code Execution Vulnerability “Click2Shell” (CVE-Unknown)

A critical-severity vulnerability chain, known as “Click2Shell” (with CVE-Unknown), has been identified in WordPress Core. The vulnerability could allow an unauthenticated attacker to use a specially crafted URL to force a logged-in WordPress administrator’s browser to install and preview an attacker-selected theme from the official WordPress.org theme directory without the administrator clicking Install or Activate. When chained with a separate vulnerability in the installed theme, the vulnerability could allow the attacker to execute arbitrary PHP code under the WordPress server account. Successful exploitation could result in full compromise of the affected website, including unauthorized access to sensitive information, modification of website content, malware installation, and service disruption.

WordPress has released security updates to address the vulnerability. System owners are strongly recommended to verify their installed WordPress version and update to the latest version immediately.

 

Vulnerability

  • WordPress Pre-Authentication Remote Code Execution Vulnerability “Click2Shell” (CVE-Unknown)
    • The installed theme may remain inactive throughout the attack, meaning the website’s appearance may not change and the compromise may not be immediately noticeable.
    • Public Proof-of-Concept (PoC) is available.

Severity Level

  • Critical

Affected Versions

  • WordPress Core versions prior to 7.1.1

Remediation

  • Update WordPress Core immediately:
    • Upgrade affected installations to WordPress 7.1.1 or later.
    • For installations remaining on an older maintained branch, apply the corresponding security release provided by WordPress.
  • Verify automatic updates:
    • System owners should verify the currently installed version instead of assuming that the update has been completed successfully.
  • Update and review installed themes:
    • Update all installed themes to their latest versions, including inactive themes.
    • Remove unused, outdated, or untrusted themes from the server instead of merely deactivating them.
  • Avoid opening untrusted links while logged in as an administrator:
    • WordPress administrators should avoid accessing links received through unsolicited emails, instant messages, websites, or other untrusted sources while an active WordPress administrator session is present.
    • Log out when administrative access is no longer required.
  • Perform a post-update security review.
  • Back up the website before updating.

 

Reference

 

 

 

Published on: 21 September 2026