Rewterz

Cisco ISE Zero-Day Vulnerability Exploited in Active Attacks

September 17, 2026
Rewterz

Microsoft SharePoint Flaw Enables Remote Code Execution

September 22, 2026

WordPress Click2Shell Flaw Enables RCE via Malicious Link

Severity

High

Analysis Summary

Researchers disclosed “Click2Shell,” a WordPress exploit chain that can potentially lead to remote code execution (RCE) through a single malicious link. The attack begins with a WordPress Core theme-preview vulnerability that allows an attacker to manipulate a theme-installation request and silently install an attacker-selected theme from the official WordPress.org directory. The flaw results from inconsistent handling of the theme value: the Themes API canonicalizes the input, while the administrator’s browser retains attacker-controlled characters and places them into a jQuery selector. By injecting selector characters, an attacker can escape the intended theme-card selection and trigger the legitimate Install control. The attack does not require a WordPress account, but it requires a logged-in administrator to visit the malicious URL, allowing the administrator’s authenticated session and nonce to perform the installation.

The forced installation alone does not provide immediate arbitrary-code execution because the selected theme is obtained from the trusted WordPress.org repository and initially remains inactive. However, researchers demonstrated that the weakness can be chained with insecure code in a vulnerable theme to achieve RCE. Using Mobile Repair Zone 2.5.4 as the example, the theme’s PHP code was loaded during a Customizer preview and exposed an authenticated AJAX handler without adequate nonce and capability checks. The handler accepted attacker-controlled plugin information and a package URL, downloaded and unpacked the supplied archive, and loaded its PHP entry point, resulting in code execution under the web server account. Successful exploitation could allow attackers to access wp-config.php and database credentials, modify website files and content, create accounts, access WordPress or WooCommerce information, steal secrets available to the PHP process, and potentially compromise the broader hosting environment.

WordPress addressed the Core vulnerability in version 7.1.1, released on September 17, 2026, as part of a security and maintenance update containing 11 security fixes, 17 Core bug fixes, and 19 Block Editor fixes. The fix, tracked in changeset 63664, restricts selector matching to a legitimate theme-card div and uses jQuery’s escapeSelector() to ensure URL-derived values are treated as literal characters rather than executable CSS selector syntax. The standalone forced-install vulnerability was assessed by pwn.ai as High severity with a CVSS 3.1 score of high, while the demonstrated chained RCE scenario was considered Critical. At the time of disclosure, WordPress had not assigned a final severity or CVE identifier, and public reporting indicated no evidence of exploitation in the wild. Researchers reported the initial issue on August 22, provided the complete RCE chain on September 1, and publicly released their technical analysis after the September 17 fix.

Organizations should immediately update WordPress to version 7.1.1 or the applicable security release for their supported branch; WordPress indicated that necessary fixes were being backported to security-supported branches through version 4.7. Administrators should verify that automatic updates are enabled, review recently installed or modified themes and plugins, and check for unexpected PHP files, user accounts, configuration changes, or other signs of compromise. Security teams should also investigate suspicious requests involving theme-install.php and Customizer-related admin-ajax.php activity, particularly where administrator sessions may have accessed malicious URLs. Because the attack relies on an authenticated administrator visiting a crafted link and can remain visually inconspicuous while the malicious theme is inactive, monitoring administrative activity and conducting post-update compromise checks are important defensive measures.

Impact

  • Code Execution
  • Gain Access

Remediation

  • Update WordPress immediately to version 7.1.1 or the latest security release available for the supported branch.
  • Enable automatic WordPress security updates where appropriate.
  • Review recently installed, updated, or modified themes and plugins for unauthorized changes.
  • Remove any unrecognized or suspicious themes and plugins, particularly those installed around the time of suspected activity.
  • Inspect the server for unexpected PHP files, modified files, web shells, and unauthorized content changes.
  • Review WordPress administrator accounts and remove unauthorized users or unexpected privilege changes.
  • Investigate suspicious requests to theme-install.php and Customizer-related admin-ajax.php endpoints.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.