A WordPress Core theme-preview selector-injection flaw, dubbed Click2Shell, can be exploited through a crafted link visited by a logged-in administrator. The attack silently installs an attacker-selected inactive theme from the official WordPress.org directory; if that theme exposes insecure pre-activation functionality, the attacker can achieve remote code execution. Researchers demonstrated the chain using Mobile Repair Zone 2.5.4, whose Customizer-preview AJAX handler could download, unpack, and execute attacker-controlled PHP. No in-the-wild exploitation was reported at disclosure.
WordPress addressed the Core flaw in version 7.1.1, including changeset 63664, and administrators should update immediately. A proposed Nuclei template, wordpress-click2shell, detected the issue on a tested WordPress 7.1 container image and did not flag WordPress 7.1.1, providing a means to identify unpatched deployments. Organizations should also review administrator session protections and restrict unnecessary themes and theme-installation privileges, since exploitation depends on an administrator loading the malicious URL.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
pwn.ai published a technical analysis of Click2Shell, rating the standalone forced-install issue High (CVSS 7.1) and the demonstrated remote-code-execution chain Critical. Public reporting at disclosure found no evidence of exploitation in the wild.
WordPress released version 7.1.1 to address the Click2Shell Core selector-injection flaw. Changeset 63664 constrained theme-card matching and applied jQuery escapeSelector() to the URL-derived slug; fixes were also being backported to supported branches through version 4.7 where needed.
Researchers delivered the complete pre-activation Click2Shell chain, demonstrating remote code execution with the Mobile Repair Zone 2.5.4 theme. Its Customizer-preview AJAX handler could download, unpack, and load attacker-controlled PHP without nonce validation or capability checks.
Researchers reported the WordPress theme-preview selector-injection and forced-install behavior that underpins the Click2Shell chain. The issue could cause a logged-in administrator visiting a crafted URL to install and preview an attacker-selected inactive theme from WordPress.org.
A WordPress core vulnerability chain dubbed wp2shell was disclosed, combining a REST API batch-processing route-confusion issue with SQL injection that could enable unauthenticated remote code execution. The WordPress Security Team released updates for affected versions and enabled automatic security updates for many sites.
A report described a potential SQL injection issue in WordPress Core's WP_Query handling of the `author__not_in` parameter, where unvalidated array elements could be inserted into a SQL `NOT IN` clause. The proposed remediation converts each supplied author ID with `intval()` before query construction.
A GitHub pull request added the `wordpress-click2shell` Nuclei detection template. Testing produced a finding on WordPress 7.1 and no finding on WordPress 7.1.1, indicating the template distinguished the tested vulnerable and fixed versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourcemedium.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.