Back to all news
Security

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

The Hacker News·September 18, 2026·1 min read
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

WordPress released patches for a new core vulnerability that lets a crafted link, opened by a logged-in admin, install a theme from the official directory without a click. Security firm pwn.ai, which reported the flaw, calls the chain Click2Shell. The flaw alone only enables theme installation, but researchers warn it can chain to code execution.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store