# WordPress Urges Immediate Patch for Click2Shell Vulnerability

*Published September 23, 2026*
*Source: [https://www.securityweek.com/wordpress-patches-click2shell-vulnerability/](https://www.securityweek.com/wordpress-patches-click2shell-vulnerability/)*

## Executive Summary

WordPress has released patches to fix a critical vulnerability called Click2Shell that could allow remote code execution via inactive themes. The flaw is significant as it enables attackers to exploit websites without administrator awareness, necessitating immediate patching.

## Article

WordPress has urgently released patches to address a critical security flaw, among ten others, that could lead to remote code execution on websites using its platform. The flaw, named Click2Shell, was discovered by cybersecurity firm pwn.ai and does not yet have an official CVE identifier. This vulnerability can be triggered by specially crafted URLs that allow unauthorized installation and preview of inactive themes on a WordPress site. While these themes remain inactive, they can be manipulated to execute PHP code, potentially giving an attacker control over the site without needing a WordPress account.

The root of the problem lies in how a specific value in the WordPress theme-preview URL is interpreted differently by the themes API and the JavaScript running in an administrator's browser. The API simplifies the value, while the browser retains it, allowing an attacker to install a theme from the WordPress.org catalog without the administrator's consent. Over 40 third-party themes are vulnerable to this exploit, as they can execute PHP code during a Customizer preview even when another theme is active.

Pwn.ai has detailed the technical aspects of the vulnerability and provided proof-of-concept code to demonstrate the exploit. They warn that the attack could go unnoticed by administrators due to the site's main theme remaining active during the exploit. WordPress has addressed the Click2Shell flaw in version 7.1.1 of its content management system. The patch is also available for older versions, going back to WordPress 4.7. The discovery earned pwn.ai a $300 reward, the maximum bug bounty offered by WordPress.
