⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

September 18, 2026

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Swati KhandelwalSep 18, 2026Vulnerability / Web Security WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only installs a real theme that the attacker picks, but the security research team showed it could be combined with a separate weakness in a theme to run the attacker's own code on the server. The fix shipped on September…