Cybersecurity Threat Advisory: WordPress "Click2Shell" Flaw Turns One Admin Click into Full Site Takeover
Threat update
A newly disclosed vulnerability in WordPress Core, nicknamed Click2Shell, allows an attacker to take control of a WordPress website if a logged-in administrator simply opens a specially crafted link. No further clicks, prompts, or approvals are needed. WordPress fixed the issue in version 7.1.1 and backported the fix to every supported branch back to 4.7. Because proof-of-concept code is now public, any organization running WordPress should confirm its sites are updated today.
Technical Detail and Additional Info
What is the threat?
Click2Shell was reported by researchers at pwn.ai and publicly disclosed on September 18, 2026, one day after WordPress released 7.1.1 with the fix. It affects WordPress versions 4.7 through 7.1.0. At the time of writing, no CVE identifier had been assigned.
The flaw sits in the WordPress theme installer. When the installer page reads a theme name from the web address, the server cleans up that value, but the browser uses the original, unfiltered text. An attacker can hide extra characters in that name to trick the admin page into pressing the "Install" button on its own. Combined with other weaknesses, this creates a chain that ends in code running on the web server:
- The bait: The attacker sends a crafted link that points to the victim's own WordPress admin area, for example by email, chat, or a support ticket.
- Silent themes install: When a logged-in administrator opens the link, WordPress uses that administrator's permissions to download and install a theme of the attacker's choosing from the official WordPress.org theme directory.
- Code runs without activation: The theme is never switched on, so the site looks unchanged. However, WordPress still loads the theme's PHP code during Customizer preview operations, which exposes any unsafe functions that theme contains.
- Remote code execution: The researchers demonstrated the chain with the Mobile Repair Zone theme (version 2.5.4), which contains a function that downloads and runs a plugin from any web address without checking permissions. According to SecurityWeek, more than 40 third-party themes could be abused in a similar way. From there, an attacker can plant a web shell, add admin accounts, or install malicious plugins.
Why is it noteworthy?
Most WordPress compromises start with a vulnerable plugin. Click2Shell is different because the entry point is WordPress Core itself, which runs on every WordPress site regardless of which plugins are installed. It also challenges a common assumption that inactive themes are harmless. Here, a theme that is never activated still provides the attacker with a way to run code.
The attack is also quiet. The visible theme never changes, so there is no obvious defacement to warn site owners. The only human action required is an administrator opening a link while signed in, which is an everyday occurrence. With a working proof of concept available, the time between disclosure and real-world attacks is likely to be short.
What is the exposure or risk?
Any organization running an unpatched WordPress site (4.7 through 7.1.0) is exposed, especially where administrators stay logged in while reading email or browsing. Sites that have automatic background updates disabled, or that are managed by a third party that has not yet applied 7.1.1, carry the highest risk.
A successful attack gives the attacker full control of the WordPress application and potentially the server. Possible outcomes include:
- Installation of web shells, backdoors, or malicious plugins that persist after the flaw is patched
- Theft of administrator credentials, customer data, or form submissions
- Website defacement or insertion of spam and phishing content that damages search rankings and brand trust
- Use of the site to distribute malware to visitors
- A foothold to move into hosting accounts or connected business systems
What are the recommendations?
LBT Technology Group recommends the following actions:
- Update WordPress to 7.1.1 or later now. If you are on an older branch, apply the latest security release for that branch. Confirm the version in the WordPress dashboard rather than assuming automatic updates ran.
- Update every theme and plugin, including inactive ones. This attack specifically abuses themes that are installed but not in use.
- Delete what you do not use. Remove unused themes and plugins, and replace any that are no longer maintained by their developer.
- Tighten administrator access. Limit the number of administrator accounts, require multi-factor authentication, and use a lower-privilege account for day-to-day content work.
- Log out of the admin area when finished. Train administrators not to open unexpected links, especially ones that point to their own site's admin pages, while signed in.
- Lock down file changes. Disable the built-in theme and plugin file editor, and restrict write permissions on the web server where possible.
- Use a web application firewall. Configure rules to flag or block unusual theme-installation requests.
- Check for signs of compromise. If your site was not updated promptly, review for unfamiliar themes, plugins, admin users, or recently changed files, then rotate administrator, hosting, and database passwords.
References
For more in-depth information about the recommendations, please visit the following links:
- pwn.ai. "Preauth WordPress Core Theme Preview Injection to RCE (Click2Shell)." September 18, 2026.
- SecurityWeek. "WordPress Patches 'Click2Shell' Vulnerability." September 22, 2026.
