New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress fixes a new vulnerability that allows attackers to install themes without user interaction, potentially leading to code execution.
Intelligence analysis by Qwen 2.5 (3B)

WordPress has patched a flaw that enables attackers to install themes without user interaction, potentially leading to code execution. The fix is available in WordPress 7.1.1.
WordPress has a new bug that lets bad guys trick people into installing a theme without them clicking 'Install'. This can let them run their own code on the server. The fix is in the latest version of WordPress.
Analysis
{"heading_1":"The Core Bug","paragraph_1":"WordPress advises updating to 7.1.1 immediately. If you cannot update at once, note that neither WordPress nor pwn.ai offered a separate workaround for this attack.","paragraph_2":"Updating WordPress core closes the demonstrated attack, regardless of the theme a site runs. The fix is available in WordPress 7.1.1, which is part of a security release that reaches supported branches back to 4.7.","paragraph_3":"The security release notes confirm this flaw from version 6.0 up through the releases just before the fix. Site owners should install 7.1.1, or the matching update for whichever branch they run, and sites set to update automatically will receive it on their own.","heading_2":"The Theme Flaw","heading_3":"Workaround and Recommendations"}
Key points
- WordPress patched a new vulnerability that allows attackers to install themes without user interaction.
- The fix is available in WordPress 7.1.1.
- The vulnerability could lead to code execution if combined with a separate weakness in a theme.
- Site owners should update to the latest version of WordPress to close the attack chain.
- The security release notes confirm this flaw from version 6.0 up through the releases just before the fix.
The fix in WordPress 7.1.1 closes the attack chain, making it harder for bad guys to exploit this vulnerability.
If the bad guys find a way to exploit this, they could run their own code on the server, which could be dangerous.


