WordPressVulnerabilities
WordPress Click2Shell vulnerability: 1-click theme install to RCE
Oct 1, 2026 · 10 min read
2 articles on this topic.

The WordPress Click2Shell vulnerability lets one admin click force a theme install that can chain to RCE. Update to WordPress 7.1.2 and check your themes.

WordPress 7.1.2 closes a critical unauthenticated file inclusion in core, now exploited in the wild. How it works, what makes it code execution, what to check.