← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 21, 2026 · 16:09via CyberInsider

WordPress Click2Shell flaw enables RCE after one admin click

Brief

WordPress has patched a vulnerability dubbed Click2Shell that could allow an attacker to silently install a theme and execute PHP code on the targeted website. The attack does not require the threat actor to have a WordPress account, but it does require a logged-in administrator to visit a specially crafted link. The vulnerability was discovered …

The post WordPress Click2Shell flaw enables RCE after one admin click appeared first on CyberInsider .

Read more on CyberInsider→