Click2Shell: WordPress Core flaw can force theme installs and chain to RCE
Researchers disclosed Click2Shell, a WordPress Core exploit chain fixed in 7.1.1 that lets an attacker trick a logged-in administrator into installing themes silently and, when combined with vulnerable themes, achieve remote code execution and full site compromise.






