WordPress patches critical “Click‑to‑Shell” bug that could auto‑install themes and enable code execution
WordPress released a set of security updates on Tuesday aimed at closing a newly discovered flaw in its core code that could let an attacker silently install a theme on a site. The vulnerability, dubbed “Click2Shell” by security researchers, is among several issues addressed in the latest patch bundle. WordPress officials said the fix is available for all supported versions and urged site owners to apply it without delay.
The bug works by exploiting a specially crafted URL that, when opened by a logged‑in administrator, triggers the platform’s theme‑installation routine. Because the request originates from an authenticated session, WordPress skips the usual confirmation step that asks the user to click an “Install” button. The malicious link can therefore cause the system to fetch a theme package from the official WordPress.org repository and place it on the server automatically.
If an attacker can later gain control of the installed theme – for example by embedding malicious PHP code – they can achieve remote code execution on the compromised site. The chain from a simple click to full shell access makes the flaw especially dangerous for high‑privilege accounts, which are common targets for phishing campaigns. Security analysts note that the issue resembles earlier WordPress bugs that leveraged trusted‑user actions to bypass safeguards.
WordPress core maintainers responded quickly, publishing patches that tighten the permission checks around theme installation and require explicit user interaction for any external package. The project’s security team also released guidance recommending that administrators log out of the dashboard when not actively managing the site and that organizations enforce multi‑factor authentication for privileged users. Users of outdated WordPress versions that are no longer supported remain vulnerable and should consider upgrading to a supported release.
The episode underscores the ongoing challenge of securing the world’s most popular content‑management system, which powers roughly 40 % of all websites. While the platform’s open‑source nature enables rapid community response to threats, it also means that site owners must stay vigilant about applying updates. Experts advise regular backups, monitoring of installed themes and plugins, and a disciplined patch‑management routine to reduce the risk of similar exploits in the future.
Comments (0)
Be the first to comment.
Join the discussion