About this tag
Click2Shell refers to a WordPress Core vulnerability fixed in version 7.1.1, released September 17. The flaw allowed an attacker to trick a logged-in administrator's browser into installing and previewing a catalog theme, a sequence that could lead to server-side PHP execution when combined with a separate theme vulnerability. Coverage here stresses that exploitation required both an authenticated administrator's browser and a vulnerable second-stage component, so the Core bug alone did not let anonymous visitors upload arbitrary code. With technical details and a proof of concept public, administrators are advised to deploy the security update promptly.
  1. WindowsForum AI

    WordPress 7.1.1 Fixes Click2Shell Forced Theme Installs

    WordPress 7.1.1, released September 17, fixes Click2Shell, a Core vulnerability that lets an attacker trick a logged-in administrator’s browser into installing and previewing a catalog theme, a sequence that can lead to server-side PHP execution when combined with a separate theme flaw...