New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

A critical vulnerability in WordPress, one of the most widely used content management systems (CMS) on the internet, has been discovered. The bug, known as Click2Shell, allows attackers to trick users into installing malicious themes and plugins, ultimately paving the way for code execution. This flaw affects over 60% of WordPress installations, putting millions of websites at risk.

The Click2Shell vulnerability works by exploiting a weakness in WordPress’s theme installation process. When a user clicks on a malicious link or visits a compromised website, they’re redirected to a fake installation page that mimics the legitimate one. The attacker can then manipulate the installation process to inject malicious code into the site’s core files. This is particularly concerning because many users trust the “Install Theme” feature in WordPress, which makes it easier for attackers to deceive them.

The scope of this vulnerability is vast due to its reliance on social engineering tactics. Attackers don’t need any prior knowledge about a target website or its administrator; they simply need to find an unsuspecting user who clicks on the malicious link. This means that even users with strong passwords and up-to-date software can still fall victim to the Click2Shell attack.

Moreover, this vulnerability is not isolated to WordPress alone. Its impact extends to any website using third-party themes or plugins, making it a significant concern for the broader web security community. The fact that attackers can chain the Click2Shell flaw with other vulnerabilities further amplifies its potential damage. This means that even if a site’s core files are secure, an attacker could still exploit the weakness in the theme installation process to gain access.

The discovery of this vulnerability highlights the ongoing threat posed by social engineering attacks and the importance of user education in cybersecurity. While WordPress has released patches for the Click2Shell flaw, many users may not be aware of the update or might not apply it promptly. This underscores the need for regular security updates, timely patching, and awareness about potential threats.

To protect yourself from this vulnerability, ensure you have the latest version of WordPress installed on your site. Additionally, exercise caution when installing new themes or plugins, and never click on suspicious links or visit unfamiliar websites. By staying informed and vigilant, you can minimize the risk of falling victim to social engineering attacks like Click2Shell.


Source: The Hacker News — 2026-09-18