WordPress Click2Shell flaw enables remote PHP execution
π‘οΈ A newly disclosed WordPress CSRF vulnerability named Click2Shell allows pre-authenticated remote code execution by forcing the installation of a theme from the WordPress.org catalog and running arbitrary PHP. The issue, fixed in WordPress 7.1.1, was reported by researcher Paulos Yibelo of pwn.ai and relies on a buggy interpretation of a theme-preview URL combined with JavaScript in the admin browser. An attacker needs no account but requires a logged-in administrator to visit a crafted link, enabling server-side code execution and potential data or file theft. Patchstack notes only administrators can trigger the chain and advises updating or enabling DISALLOW_FILE_MODS as a temporary mitigation.