Smartermsp iconSmartermspSep 25, 2026 ~4 min source read

Click2Shell: WordPress Core flaw can force theme installs and chain to RCE

Researchers disclosed Click2Shell, a WordPress Core exploit chain fixed in 7.1.1 that lets an attacker trick a logged-in administrator into installing themes silently and, when combined with vulnerable themes, achieve remote code execution and full site compromise.

Cybersecurity Threat Advisory: WordPress Click2Shell flaw enables RCE

Share this story

Send the public story page.

Useful takeaways from this story.

Limit admin exposure: enforce MFA, restrict who has administrator privileges, avoid using admin sessions for routine browsing.

Monitor wp-content/themes and admin requests for unexpected installs, and rotate credentials and inspect logs if compromise is suspected.

# What happened

# Why this matters

Click2Shell affects WordPress Core rather than a single plugin or theme. The attack challenges the assumption that inactive themes are harmless because preview functionality can make inactive theme code reachable. Because newly installed themes and plugins can remain invisible to administrators, an attacker who chains Click2Shell with a vulnerable theme can achieve remote code execution (RCE) and persistent control while leaving the visible theme unchanged, making detection harder.

# Risk and likely impacts

If an environment is unpatched and an administrator visits a malicious link, the possible outcomes include:

  • Unauthorized installation of themes or plugins
  • Remote code execution and PHP execution on the server
  • Deployment of web shells and persistent access
  • Credential theft, data manipulation, and site defacement
  • Use of the site to host malware or phishing pages

Risk increases when administrators browse external sites or email while logged into WordPress, and when environments permit theme and plugin changes through the dashboard.

# Concrete actions to take now

  • Upgrade WordPress Core to version 7.1.1 or later.
  • If an immediate major upgrade isn't possible, apply available security updates for supported branches.
  • Patch all installed themes and plugins, including inactive ones.
  • Remove unsupported or abandoned plugins and themes.
  • Review for themes named in research (for example, Mobile Repair Zone 2.5.4) and remove or patch them.
  • Disable direct theme and plugin editing and restrict file write permissions to required directories.
  • Consider disabling theme and plugin installation in production environments.
  • Limit administrator privileges to required personnel.
  • Enable multi-factor authentication for admin accounts.
  • Avoid using admin sessions for routine web browsing and require reauthentication for sensitive actions.
  • Monitor for unexpected additions under wp-content/themes/.
  • Review logs for access to /wp-admin/theme-install.php, /wp-admin/admin-ajax.php, and Customizer-related requests.
  • Investigate new themes/plugins, unexpected PHP files, and recently modified theme files.

Containment and response if you suspect exposure

  • Search for unexpected themes or plugins and remove them.
  • Examine administrative and web server logs for suspicious activity and the entry point URL.
  • Rotate administrator credentials and revoke active sessions if compromise is suspected.

# Practical defensive tools

  • Use a web application firewall with rules to detect suspicious theme-installation activity and block requests with abnormal theme parameters.
  • Train administrators to avoid clicking unsolicited links while logged into WordPress and use separate browser profiles for administration.

# Bottom line

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app