{
  "id": 12517010,
  "title": "Finding WordPress Click2Shell Exposure Starts With Knowing Where WordPress Runs",
  "url": "https://urgent.news/2026/10/07/finding-wordpress-click2shell-exposure-starts-with-knowing-where",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T01:40:34.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/onaeiuspkz/finding-wordpress-click2shell-exposure-starts-with-knowing-where-wordpress-runs-2kpb"
  },
  "original_language": "en",
  "account": "On September 21, 2026, security researchers unveiled Click2Shell, an unauthenticated remote code execution vulnerability in WordPress Core. With no WordPress account required, a single visit from a logged-in administrator to a crafted link is sufficient. The browser installs a theme on its own, then the theme's unprotected AJAX endpoint downloads and executes attacker-controlled PHP. WordPress patched the core parser flaw in version 7.1.1, though no CVE identifier has been published yet, and researchers confirmed no exploitation in the wild at the time of discovery. To prioritize a fix, organizations first need to understand where WordPress actually runs within their environments. With 7,945,496 matching assets worldwide, the scale of potential vulnerability is immense. However, not all of these instances are vulnerable, nor are they already attacked. ZoomEye played a crucial role in this discovery by providing verifiable asset identification through fingerprint queries. While the count represents a point-in-time observation and does not confirm specific patch levels, it serves as a critical starting point for patch tracking, theme audits, and incident review. For organizations, identifying all WordPress instances, especially those running forgotten or unofficial themes, is the first essential step in managing the risk posed by Click2Shell and future vulnerabilities.",
  "summary": "Finding WordPress Click2Shell Exposure Starts With Knowing Where WordPress Runs On September 21, 2026, security researchers disclosed Click2Shell, an unauthenticated remote code execution chain in WordPress Core. An attacker needs no WordPress account. A single visit by a logged-in administrator to a crafted link is enough: the browser installs a catalog theme on its own, and the theme's…",
  "key_points": [
    "Click2Shell vulnerability discovered in WordPress Core on September 21, 2026",
    "No WordPress account needed for exploitation, single admin visit to crafted link",
    "ZoomEye helped identify 7.9 million WordPress instances worldwide"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}