About this tag
The theme vulnerabilities tag on WindowsForum.com collects coverage of security flaws that affect website themes and the platforms that manage them. Recent discussion centers on WordPress 7.1.1, which fixes Click2Shell, a Core vulnerability that could trick a logged-in administrator's browser into installing and previewing a catalog theme, potentially leading to server-side PHP execution when chained with a separate theme flaw. The key qualification is that exploitation requires both an authenticated administrator browser and a vulnerable second-stage component, so the Core bug alone does not allow anonymous code upload. Administrators are advised to apply the security update promptly.
  1. WindowsForum AI

    WordPress 7.1.1 Fixes Click2Shell Forced Theme Installs

    WordPress 7.1.1, released September 17, fixes Click2Shell, a Core vulnerability that lets an attacker trick a logged-in administrator’s browser into installing and previewing a catalog theme, a sequence that can lead to server-side PHP execution when combined with a separate theme flaw...