• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

Admin by Admin
September 18, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalSep 18, 2026Vulnerability / Internet Safety

WordPress at this time launched patches to repair a brand new set of vulnerabilities in its core software program, certainly one of which may enable a crafted internet hyperlink, opened by a logged-in administrator, to put in a theme from the official WordPress.org listing with out anybody clicking Set up.

The safety agency pwn.ai, whose researchers reported the flaw, calls the assault chain Click2Shell. By itself the flaw solely installs an actual theme that the attacker picks, however the safety analysis workforce confirmed it could possibly be mixed with a separate weak point in a theme to run the attacker’s personal code on the server. 

The repair shipped on September 17 in WordPress 7.1.1. As a result of it is a safety launch, WordPress advises updating immediately. There isn’t a signal the flaw has been utilized in actual assaults.

The put in theme stays switched off, so the location’s personal look doesn’t change and nothing appears to be like mistaken. Reaching code execution wanted a second, separate flaw within the theme that was put in. As pwn.ai wrote of the core bug alone, “The Core bug doesn’t settle for an arbitrary theme ZIP by itself.”

The flaw works as a result of two elements of WordPress learn the identical hyperlink in another way. The WordPress.org listing treats the worth within the hyperlink as an atypical theme identify and returns an actual theme, however the administrator’s browser reuses the unique textual content, punctuation and all, inside code meant to select an merchandise on the web page. Characters the attacker provides to the hyperlink ship that code to the Set up button, and WordPress’s personal script clicks it.

As a result of the administrator is already logged in, their session provides the permission and the safety token the set up wants, so the attacker provides neither.

An put in theme is just not at all times idle. When WordPress builds a preview in its Customizer device, it will possibly load a theme’s PHP code even earlier than the theme is switched on.

The theme pwn.ai used, Cell Restore Zone, carried a second flaw: a background handler that fetched an online tackle from the request, downloaded a package deal, and ran its code, with no test on the customer’s permission or a safety token. Chained after the compelled set up, that handler ran the attacker’s code on the server.

The researchers rated the forced-install flaw by itself as excessive severity, with a CVSS rating of seven.1, and the total chain to code execution as vital, at 9.6. WordPress has not revealed a severity score of its personal, and in its launch it described the problem this fashion: “Specifically crafted URLs can robotically set up and preview an inactive theme from WordPress.org.” No CVE identifier has been assigned but, although pwn.ai says WordPress plans so as to add one.

WordPress fastened the flaw in 7.1.1, a part of a safety launch whose fixes attain supported branches again to 4.7. Its notes affirm this flaw from model 6.0 up by means of the releases simply earlier than the repair. Web site house owners ought to set up 7.1.1, or the matching replace for whichever department they run, and websites set to replace robotically will obtain it on their very own.

Should you can’t replace directly, word that neither WordPress nor pwn.ai supplied a separate workaround, and that the assault nonetheless wants a logged-in administrator to open the attacker’s hyperlink. Updating WordPress core closes the demonstrated assault no matter theme a website runs.

Click2Shell is just not the agency’s first WordPress core flaw in latest weeks. In August, WordPress fastened the same flaw pwn.ai discovered within the login display screen and likewise chained to code execution, and there too WordPress described the danger extra narrowly than the researchers did.

A completely different WordPress core flaw disclosed in July, referred to as wp2shell, is just not linked to pwn.ai’s work. That flaw wants no login and no click on, and the U.S. cybersecurity company CISA has listed it as exploited in actual assaults, which Click2Shell has not been.

Tags: ChainClick2ShellCodeExecutionFlawForcesinstallsthemeWordPress
Admin

Admin

Next Post
27 years later, EverQuest Legends is simply getting began

27 years later, EverQuest Legends is simply getting began

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Search Expertise Optimization (SXO): A Full Information

Search Expertise Optimization (SXO): A Full Information

February 2, 2026
US Scrambles to Patch F5 Amid China-Linked Breach

US Scrambles to Patch F5 Amid China-Linked Breach

October 20, 2025

Trending.

AI & data-driven Starbucks – Deep Brew

AI & data-driven Starbucks – Deep Brew

May 18, 2026
Meet FreeToken: An Edge-Native MoE Serving Engine that Runs 753B GLM-5.2 on a Single Workstation GPU

Meet FreeToken: An Edge-Native MoE Serving Engine that Runs 753B GLM-5.2 on a Single Workstation GPU

August 23, 2026
Attackers Exploit MCP RCE, Blind Immediate Injection and Reminiscence Credential Theft Towards AI Infrastructure

Attackers Exploit MCP RCE, Blind Immediate Injection and Reminiscence Credential Theft Towards AI Infrastructure

August 29, 2026
The Full Information to EcoGPT

The Full Information to EcoGPT

June 6, 2026
Is ClickUp Price It in 2026? My Trustworthy ClickUp Evaluate

Is ClickUp Price It in 2026? My Trustworthy ClickUp Evaluate

March 1, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

27 years later, EverQuest Legends is simply getting began

27 years later, EverQuest Legends is simply getting began

September 18, 2026
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

September 18, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved