A critical vulnerability in WordPress has been disclosed, allowing attackers to install malicious themes on affected sites. The Click2Shell flaw, discovered by security researchers, can lead to code execution and potentially devastating consequences for website owners and their visitors.
The issue stems from a misconfigured setting that allows an attacker to exploit the theme installation feature without user interaction. This means that once an attacker gains access to a vulnerable site, they can install any theme they choose, including those designed to deliver malware or conduct malicious activities. The Click2Shell vulnerability is particularly concerning because it can be chained with other exploits, allowing attackers to execute arbitrary code on the affected server.
WordPress is one of the most widely used content management systems (CMS) online, powering millions of websites worldwide. As a result, the scope of this vulnerability is significant, and website owners must take immediate action to protect themselves. The Click2Shell flaw affects all WordPress versions prior to 5.8, which was released earlier this year. This means that site administrators who have not updated their software in recent months are at risk.
To understand how the Click2Shell exploit works, consider what happens when an attacker gains access to a vulnerable site. They can use the theme installation feature to upload and install any theme they choose, regardless of its origin or contents. Once installed, the theme is executed by WordPress, allowing the attacker to execute arbitrary code on the affected server. This opens up a range of possibilities for malicious activities, including data theft, website defacement, and even ransomware attacks.
The Click2Shell vulnerability highlights the importance of keeping software up-to-date and regularly reviewing site security settings. Website owners must take proactive steps to protect themselves from this and other known vulnerabilities. The most effective way to mitigate the risk is to update WordPress to version 5.8 or later, which includes patches for the Click2Shell flaw.
In light of this vulnerability, we urge all website owners using WordPress to take immediate action. Update your software to the latest version, review your site’s security settings, and conduct regular backups of your data. By taking these simple steps, you can significantly reduce the risk of falling victim to this or other similar attacks.
Source: The Hacker News — 2026-09-18