URL has been copied successfully!
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link