WordPress Click2Shell Vulnerability Enables Remote PHP Code Execution

Sep 22, 2026

A newly disclosed WordPress vulnerability, dubbed Click2Shell, allows attackers to execute arbitrary PHP code on vulnerable websites through a cross-site request forgery (CSRF) attack chain. The vulnerability affects WordPress Core versions 7.1.0 and earlier and was addressed in WordPress 7.1.1.

Discovered by security researcher Paulos Yibelo of pwn.ai, the flaw enables attackers to force-install a theme from the official WordPress.org catalog and execute malicious PHP code through the WordPress Customizer. Although the attack does not require the attacker to authenticate, a logged-in administrator must visit a specially crafted URL for the exploit to work.

Key Facts of the Incident

Category

Details

Vulnerability Name

Click2Shell

Threat Type

Cross-Site Request Forgery (CSRF) leading to Remote Code Execution

Affected Software

WordPress Core 7.1.0 and earlier

Fixed Version

WordPress 7.1.1

Attack Mechanism

Forced theme installation followed by PHP code execution through Customizer preview

Authentication Required

No attacker account required, but a logged-in administrator must visit a crafted URL

Researcher

Paulos Yibelo, pwn.ai

Disclosure Date

September 21, 2026

Potential Impact

Arbitrary PHP execution, file modification, data access, and malicious administrator account creation

Recommended Mitigation

Update WordPress to version 7.1.1 or later and apply additional security controls

What Happened?

Security researcher Paulos Yibelo reported the Click2Shell vulnerability to WordPress on August 22, 2026. The flaw involves the way WordPress processes theme preview URLs and how JavaScript in an administrator's browser handles the resulting data.

According to the research, a value from a WordPress theme-preview URL is processed by the WordPress.org Themes API and then handled incorrectly by JavaScript in the administrator's browser. This enables an attacker to trigger the installation of a theme without the administrator explicitly installing it.

The attack works through the following sequence:

  1. Crafted Malicious Link: An attacker prepares a specially crafted URL designed to exploit the WordPress theme preview functionality.

  2. Administrator Interaction: A logged-in WordPress administrator visits the malicious link.

  3. Unauthorized Theme Installation: The vulnerability allows a theme from the official WordPress.org catalog to be installed without the administrator intentionally initiating the installation.

  4. Customizer Preview: The installed theme is loaded through the WordPress Customizer, where its PHP code can be executed.

  5. Remote Code Execution: The attacker achieves server-side execution of arbitrary PHP code through the exploit chain.

The attack requires administrator interaction, but the attacker does not need a WordPress account, installation nonce, or administrative privileges of their own.

Technical Details

Cross-Site Request Forgery (CSRF)

Click2Shell exploits a vulnerability in WordPress Core's handling of theme-preview functionality. The flaw allows an attacker to manipulate requests initiated through an administrator's browser.

The vulnerability involves the processing of theme slugs in WordPress JavaScript. WordPress addressed the issue in version 7.1.1 by escaping the theme slug before using it in a jQuery selector and restricting the selector to actual theme cards.

Arbitrary PHP Code Execution

The vulnerability becomes particularly serious when combined with a vulnerable theme. During the Customizer preview, PHP code associated with the theme can execute on the server.

In a proof-of-concept demonstration, pwn.ai used a vulnerable WordPress theme to execute attacker-controlled PHP code. The researcher also published technical details and a proof-of-concept exploit.

No Direct Attacker Authentication Required

Unlike conventional attacks that require an attacker to log in to a WordPress account, Click2Shell does not require the attacker to have their own account or administrative permissions.

However, the attack depends on a logged-in administrator visiting a crafted URL. This makes targeted phishing and other administrator-focused attack techniques relevant to the vulnerability's exploitation.

Potential Impact & Risks

Successful exploitation could allow attackers to execute malicious PHP code on the affected WordPress server. Depending on the server's permissions and configuration, this could lead to:

  • File Modification and Deletion: Attackers could alter or remove website files.

  • Sensitive Data Exposure: Attackers could access website data, including information stored in wp-config.php.

  • Database Credential Theft: The wp-config.php file may contain database credentials and authentication secrets.

  • Unauthorized Administrator Accounts: Attackers could create rogue administrator accounts.

  • Malicious Script Injection: Attackers could inject malicious scripts into websites.

  • Server-Side Remote Code Execution: Attackers could execute arbitrary PHP code on the server.

The actual impact depends on the website's configuration, server permissions, and the level of access available to the executed code.

Who Is at Risk?

The vulnerability affects WordPress Core version 7.1.0 and earlier. The underlying flaw could be used to force-install vulnerable themes from the official WordPress.org catalog.

Patchstack's analysis highlights that the attack requires an administrator-level account to trigger the relevant functionality. Author and Editor accounts do not have the necessary permissions to install themes.

Organizations running WordPress websites should pay particular attention to:

  • Websites operating on outdated WordPress versions.

  • Administrators who frequently access links from emails or external messages.

  • Websites that allow theme installation and modification.

  • WordPress installations without adequate access controls and monitoring.

What Organizations Should Do

1. Update WordPress Immediately

Organizations should update WordPress to version 7.1.1 or later, where the Click2Shell vulnerability has been addressed.

The availability of a public proof-of-concept makes timely patching particularly important.

2. Restrict Theme and Plugin Installation

Patchstack recommends enabling the DISALLOW_FILE_MODS configuration where appropriate. This can prevent forced installation of themes or malicious plugins, although it may also restrict legitimate website management activities.

3. Strengthen Administrator Security

Administrators should exercise caution when opening links received through email or other communication channels. Organizations should also apply appropriate access controls and monitor administrator activity.

4. Review Website Integrity

Security teams should inspect websites for unexpected changes, unauthorized administrator accounts, suspicious scripts, and other indicators of compromise if exploitation is suspected.

5. Conduct Security Testing

Organizations can use authorized vulnerability assessments and penetration testing to identify weaknesses in WordPress configurations, administrative workflows, and access controls.

Why This Matters

The Click2Shell vulnerability highlights how a seemingly ordinary administrator interaction can become part of a server-side remote code execution attack.

While the vulnerability requires a logged-in administrator to visit a crafted link, the attack chain demonstrates the security risks associated with combining browser-based request manipulation, theme installation, and server-side code execution.

For security teams, patch management and administrator-focused security awareness should work together. Updating WordPress addresses the underlying vulnerability, while educating administrators about malicious links can help reduce the likelihood of successful social engineering attacks.

Organizations should prioritize timely updates, restrict unnecessary administrative capabilities, and regularly assess the security of their WordPress environments.

Latest News

WordPress Click2Shell Vulnerability Enables Remote PHP Code Execution

WordPress Click2Shell Vulnerability Enables Remote PHP Code Execution

WordPress Click2Shell Vulnerability Enables Remote PHP Code Execution

WordPress Click2Shell Vulnerability Enables Remote PHP Code Execution

WordPress Click2Shell Vulnerability Enables Remote PHP Code Execution

Sep 22, 2026

Chinese Hackers Use SparroWocky Malware in Government Espionage Attacks

Chinese Hackers Use SparroWocky Malware in Government Espionage Attacks

Chinese Hackers Use SparroWocky Malware in Government Espionage Attacks

Chinese Hackers Use SparroWocky Malware in Government Espionage Attacks

Chinese Hackers Use SparroWocky Malware in Government Espionage Attacks

Sep 17, 2026

Trezor Phishing Attack Targets 347,000 Users After Brevo Breach

Trezor Phishing Attack Targets 347,000 Users After Brevo Breach

Trezor Phishing Attack Targets 347,000 Users After Brevo Breach

Trezor Phishing Attack Targets 347,000 Users After Brevo Breach

Trezor Phishing Attack Targets 347,000 Users After Brevo Breach

Sep 14, 2026

Nearly 700 Rogue AI Agents Coordinated Hugging Face Cyberattack

Nearly 700 Rogue AI Agents Coordinated Hugging Face Cyberattack

Nearly 700 Rogue AI Agents Coordinated Hugging Face Cyberattack

Nearly 700 Rogue AI Agents Coordinated Hugging Face Cyberattack

Nearly 700 Rogue AI Agents Coordinated Hugging Face Cyberattack

Sep 2, 2026

Critical Elementor Pro Vulnerability Enables Remote Code Execution on WordPress Sites

Critical Elementor Pro Vulnerability Enables Remote Code Execution on WordPress Sites

Critical Elementor Pro Vulnerability Enables Remote Code Execution on WordPress Sites

Critical Elementor Pro Vulnerability Enables Remote Code Execution on WordPress Sites

Critical Elementor Pro Vulnerability Enables Remote Code Execution on WordPress Sites

Aug 21, 2026

Anthropic to Watermark Claude AI-Generated Text With Invisible Signals

Anthropic to Watermark Claude AI-Generated Text With Invisible Signals

Anthropic to Watermark Claude AI-Generated Text With Invisible Signals

Anthropic to Watermark Claude AI-Generated Text With Invisible Signals

Anthropic to Watermark Claude AI-Generated Text With Invisible Signals

Aug 17, 2026

Get updates in your inbox directly

You are now subscribed.

Get updates in your inbox directly

You are now subscribed.

Get updates in your

inbox directly

You are now subscribed.

Get updates in your inbox directly

You are now subscribed.

Enable your employees as first line of defense and expand your digital footprints without any fear.

Enable your employees as first line of defense and expand your digital footprints without any fear.

Enable your employees as first line of defense and expand your digital footprints without any fear.

Enable your employees as first line of defense and expand your digital footprints without any fear.