Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link
ID: 00f6b3d5-3344-5e5e-82fa-821f351716c9
STIX ID: report--00f6b3d5-3344-5e5e-82fa-821f351716c9
Feed Name: cybersecurityNews.com
Researchers disclosed "Click2Shell," a WordPress Core selector-injection and forced-install weakness that can be chained with insecure theme pre-activation code to convert a single malicious link (visited by a logged-in administrator) into remote code execution. WordPress patched the core selector issue in version 7.1.1 (Sep 17, 2026); site owners are urged to update, verify recent theme installs, inspect for unexpected PHP files and suspicious requests, and ensure automatic updates are enabled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
