New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
High · The Hacker News ·
WordPress
What happened
WordPress patched core flaws; a crafted link opened by a logged-in admin can silently install a WordPress.org theme, called Click2Shell, and may chain to code execution. Affected: WordPress sites/admins.
What to do now
Patch WordPress core immediately to the latest release; verify version. Enforce MFA, limit admin accounts, review/remove unknown themes, monitor logs for theme installs. Don't open untrusted links while logged in. If delayed, restrict admin access/WAF. Verify with vendor advisory.
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.