Summary
WordPress has released version 7.1.1 to patch a vulnerability chain named Click2Shell by its discoverers at pwn.ai. The chain begins with a forced-install flaw rated CVSS 7.1: a specially crafted link, when opened by a logged-in WordPress administrator, silently installs a theme from the official WordPress.org directory without the administrator clicking Install. The flaw exploits a difference in how WordPress.org and the administrator’s browser parse the same link, so the administrator’s active session supplies both the permission and the security token the installation requires. When the forced-install flaw is chained with a secondary vulnerability in the installed theme, the full attack escalates to PHP code execution on the server, rated CVSS 9.6. The affected versions span WordPress 6.0 through 7.1.0 across all supported branches. WordPress 7.1.1 patches the forced-install flaw and is available across all supported branches back to 4.7.
Timeline
| Date | Event |
|---|---|
| September 2026 | pwn.ai researchers discover Click2Shell forced-install flaw and the chain to code execution via Mobile Repair Zone theme secondary vulnerability; reported to WordPress security team |
| Sep 18, 2026 | WordPress releases version 7.1.1 patching the Click2Shell forced-install flaw across all supported branches; The Hacker News and BleepingComputer report full chain details |
| Sep 21, 2026 | TTO-2026-0921-149 published |
What Happened
The forced-install flaw at the root of Click2Shell exploits an inconsistency in how WordPress.org’s theme directory and an administrator’s browser interpret a specially crafted URL. When an administrator who is logged into their WordPress dashboard clicks a malicious link, their browser resolves the link as an installation request rather than a navigation. Because the administrator is already authenticated, their active session supplies both the capability permission and the nonce security token the installation workflow requires — the attacker supplies neither. The result is that a theme from the official WordPress.org directory is installed on the victim’s site without any deliberate action by the administrator beyond clicking a link.
An installed theme is not automatically inert. When WordPress builds a preview in its Customizer tool, it can load a theme’s PHP code even before the theme is switched to active. pwn.ai identified that the Mobile Repair Zone theme — a legitimate theme present in the official WordPress.org directory — contains a secondary vulnerability: a background handler that fetches a web address from the HTTP request, downloads a package from that address, and executes the downloaded code, with no check on visitor permission or a security token. Chained after the forced install, that handler executes the attacker’s code on the server in the context of the web server process.
The two-stage chain means the attack surface is broader than it first appears. The initial forced-install flaw requires only that an administrator open a crafted link while logged in — a standard phishing or link-sharing scenario. The secondary theme flaw then converts a theme directory listing into a code execution path. WordPress has patched the forced-install flaw in 7.1.1. Sites set to automatic updates will receive the patch on their own. Administrators who cannot update immediately have no separate workaround for the Click2Shell flaw and should treat any unexpected theme installations as a potential indicator of exploitation.
Domain Intelligence
wordpress.org — 60.45
wordpress.org scores in the low-trust range at 60.45. WordPress.org is the official distribution and update platform for the WordPress software and the party that patched the Click2Shell flaw in version 7.1.1. The score carries a T6_CONSUMER_REPUTATION_PENALTY flag reflecting consumer-facing reputation signals in the engine’s T6 layer rather than infrastructure deficiencies. This flag does not indicate a security concern about wordpress.org itself.
The Trust Observatory · thetrustobservatory.com · September 21, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026