← All articles

WordPress flaw forces theme installs and can chain to server code execution

WordPress shipped 7.1.1 on September 17 to fix a flaw that pwn.ai calls Click2Shell, where a crafted link opened by a logged-in administrator installs a theme from the official directory with no click. Two parts of WordPress read the link differently, so attacker-added characters steer the admin browser into clicking Install, and the logged-in session supplies the permission and security token. Alone it only installs a real, switched-off theme, but the researchers chained it with a second flaw in the Mobile Repair Zone theme, whose handler fetched and ran remote code during a Customizer preview, reaching server code execution. No in-the-wild abuse is reported.

Check
Update all WordPress sites to 7.1.1 immediately, then audit installed themes for unexpected additions and remove any that administrators did not intend.
Affected
Sites where an administrator opens a crafted link can silently install an attacker-chosen theme, which can chain with a vulnerable theme to code execution.
Fix
Apply 7.1.1, remove unused themes, and warn administrators against opening untrusted links while authenticated to the WordPress dashboard.