Security
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
The Hacker News·September 18, 2026·1 min read
WordPress released patches for a new core vulnerability that lets a crafted link, opened by a logged-in admin, install a theme from the official directory without a click. Security firm pwn.ai, which reported the flaw, calls the chain Click2Shell. The flaw alone only enables theme installation, but researchers warn it can chain to code execution.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
