# WordPress fixes Click2Shell flaw as proof-of-concept code becomes public

_Published Monday, September 21, 2026 at 11:10 PM EDT · Security · Latest · Tier 1 — Major_

![WordPress fixes Click2Shell flaw as proof-of-concept code becomes public — Primary](https://www.bleepstatic.com/content/hl-images/2026/04/15/WordPress.jpg)

Technical details and proof-of-concept code were published for Click2Shell, a WordPress Core vulnerability fixed in version 7.1.1. The attack chain can make a logged-in administrator's browser install a vulnerable catalog theme and execute its PHP code on the server, even though the attacker needs no WordPress account.

Successful exploitation could expose user data and configuration secrets, modify files or create rogue administrators. The flaw affects WordPress Core 7.1.0 and earlier, but the administrator must visit a crafted link and lower-privileged Author or Editor accounts cannot trigger the chain.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/)

---
Canonical: https://techandbusiness.org/newswire/9PX4gRovyuxp6QMRT901M2
Published: 2026-09-22T03:10:04.927Z
Story chronology: 2026-09-21T18:23:11.000Z
Retrieved: 2026-09-22T05:07:24.383Z
Publisher: Tech & Business (techandbusiness.org)
