← Back to Tech & Science

WordPress Patches Critical Click2Shell Flaw Allowing Unauthorized Theme Installs

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SAN FRANCISCO — The WordPress security team released emergency patches on Thursday to address a critical vulnerability in the core software that allowed attackers to force theme installations and execute arbitrary code through malicious links. The update, issued at 5:10 p.m. UTC on Sept. 18, 2026, targets a flaw dubbed "Click2Shell," which researchers from pwn.ai identified as a significant risk to the global network of websites running the content management system.

The vulnerability exploited a gap in WordPress's theme installation mechanism. By luring site administrators or visitors with specifically crafted URLs, attackers could bypass standard security checks to install unauthorized themes without user consent. Once a malicious theme was installed, the flaw allowed for a chain reaction that escalated privileges, enabling remote code execution on the affected server. This capability would grant attackers full control over the compromised site, potentially allowing them to steal data, deface content, or use the server as a launching point for further attacks against other systems.

WordPress.org confirmed the release of the patches across all supported versions of its core software. The update is designed to close the specific logic error that permitted the unauthorized installation process and sever the path to code execution. Site administrators were urged to apply the security update immediately to mitigate the risk. The widespread adoption of WordPress, which powers a significant portion of the internet's websites, underscores the urgency of the patch deployment.

Researchers from pwn.ai, who first disclosed the issue, detailed how the Click2Shell vulnerability functioned as a zero-click or low-interaction exploit in certain configurations. Their analysis indicated that the flaw did not require complex social engineering beyond the distribution of a single malicious link to trigger the initial compromise. The security team acknowledged the severity of the finding and coordinated the rapid release of the fix to prevent widespread exploitation.

While the core vulnerability has been patched, questions remain regarding the extent of any prior exploitation in the wild. Security experts are currently monitoring web traffic for signs that the flaw was weaponized before the public disclosure on Thursday. Additionally, administrators of older or unsupported versions of WordPress face continued risk if they cannot upgrade to a patched version immediately.

The incident highlights ongoing challenges in securing widely used open-source platforms against sophisticated supply chain and installation-based attacks. As the community applies the updates, security firms are advising users to audit their systems for any signs of unauthorized theme installations or anomalous code changes that may have occurred during the window of exposure. The situation remains fluid as investigators assess whether the vulnerability was actively exploited by threat actors in the days leading up to the patch release.

Discussion

0 / 2000