WordPress Pre-Authentication Remote Code Execution Vulnerability “Click2Shell” (CVE-Unknown)

A critical-severity vulnerability chain, known as “Click2Shell” (with CVE-Unknown), has been identified in WordPress Core. The vulnerability could allow an unauthenticated attacker to use a specially crafted URL to force a logged-in WordPress administrator’s browser to install and preview an attacker-selected theme from the official WordPress.org theme directory without the administrator clicking Installor Activate. When chained with a separate vulnerability in the installed theme, the vulnerability could allow the attacker to execute arbitrary PHP code under the WordPress server account. Successful exploitation could result in full compromise of the affected website, including unauthorized access to sensitive information, modification of website content, malware installation, and service disruption.

WordPress has released security updates to address the vulnerability. System owners are strongly recommended to verify their installed WordPress version and update to the latest version immediately.

For details, please visit: