Close Menu
NCIJ Network NCIJ Network
    What's Hot

    UNGA 2026: The U.N. Sustainable Development Goals Are Outdated

    September 21, 2026

    Did Broncos quarterback Bo Nix rebuke Trump for calling female reporter a pig?

    September 21, 2026

    Former ‘death squad’ leader appears in military trial in The Gambia | Courts News

    September 21, 2026
    Facebook X (Twitter) Instagram
    Trending
    • UNGA 2026: The U.N. Sustainable Development Goals Are Outdated
    • Did Broncos quarterback Bo Nix rebuke Trump for calling female reporter a pig?
    • Former ‘death squad’ leader appears in military trial in The Gambia | Courts News
    • EU deadlocked over France’s bid to take Russian tycoon off sanctions list – POLITICO
    • Andy Burnham says UK to provide Saudi Arabia with ‘defensive’ support
    • OpenAI forms math advisory group as its AI resolves more than 100 open problems
    • CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast
    • Bitcoin ETF Holders Back In The Black As Price Barrels Towards $87,000
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 21
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    WordPress Click2Shell flaw lets hackers execute PHP on the server

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 21, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed ‘Click2Shell’ that affects the platform’s Core component.

    The security problem does not have an official identifier but was addressed last week with the release of WordPress version 7.1.1.

    It is a pre-authenticated remote code execution chain that allows an attacker to install any theme in the official WordPress.org catalog and run an arbitrary PHP file.

    Security researcher Paulos Yibelo of the autonomous penetration testing platform pwn.ai discovered Click2Shell and reported it to WordPress on August 22.

    The researchers explain that “a value from a WordPress theme-preview URL is interpreted once by the WordPress.org Themes API and a second, buggy methods by JavaScript in the Administrator’s browser.”

    This enables an attacker to add a WordPress theme to a target website without the administrator explicitly installing it. The researcher found that even if inactive, a theme could still execute PHP during a Customizer preview.

    It should be noted that even if the attacker does not need to authenticate, a logged-in administrator needs to visit a crafted URL for the Click2Shell exploit to work.

    An attack could start with a crafted link that leads to installing a vulnerable theme in the catalog. Once the Customizer preview loads the inactive theme’s PHP, the code is executed on the server.

    To demonstrate the issue, pwn.ai used a vulnerable WordPress theme as the second component in the chain that executed the attacker’s PHP code.

    The researcher’s full technical report provides a complete proof-of-concept (PoC) exploit for achieving server-side remote code execution.

    Executing code this way could enable file modification and deletion, access to user data, and the ‘wp-config.php’ file that contains database credentials and authentication secrets. An attacker could leverage this access to create rogue admin accounts or inject malicious scripts.

    Although Yibelo demonstrated Click2Shell using a particular theme, the underlying flaw in WordPress Core 7.1.0 and earlier could be leveraged to force-install any other vulnerable theme in the WordPress catalog.

    The researcher notes that an attacker does not need a WordPress account, an installation nonce, or their own administrative privileges. However, a Click2Shell attack requires a logged-in administrator to visit the crafted link.

    WordPress security firm Patchstack analyzed Click2Shell and highlights that only an administrator can trigger the chain, while Author and Editor accounts lack the required permission to install themes.

    The company warned that attacks are possible via targeted phishing or an existing cross-site scripting (XSS) flaw that makes the administrator’s browser send the request.

    WordPress fixed the Core vulnerability in version 7.1.1 by escaping the theme slug before using it in the jQuery selector and restricting the selector to actual theme cards.

    For administrators who cannot install the update immediately, Patchstack says that websites with ‘DISALLOW_FILE_MODS’ enabled cannot be forced to install the theme or a malicious plugin.

    However, switching to the latest WordPress version is a strong recommendation, especially with complete technical details and a PoC already public.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Click2Shell Execute Flaw hackers lets PHP server WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast

    Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

    Google Hit With $463 Million Fine for EU Location Data Rule Breach

    TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

    Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

    ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    UNGA 2026: The U.N. Sustainable Development Goals Are Outdated

    September 21, 2026

    Did Broncos quarterback Bo Nix rebuke Trump for calling female reporter a pig?

    September 21, 2026

    Former ‘death squad’ leader appears in military trial in The Gambia | Courts News

    September 21, 2026

    EU deadlocked over France’s bid to take Russian tycoon off sanctions list – POLITICO

    September 21, 2026
    Latest Posts

    Google Assistant will disappear from your phone next month

    August 5, 2026

    Pope Leo Will Visit Peru, Where He Lived for Years, in November

    August 5, 2026

    Forget the goals and PBs – just enjoy it | Sport

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    UNGA 2026: The U.N. Sustainable Development Goals Are Outdated

    September 21, 2026

    Did Broncos quarterback Bo Nix rebuke Trump for calling female reporter a pig?

    September 21, 2026

    Former ‘death squad’ leader appears in military trial in The Gambia | Courts News

    September 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.