← registry

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

A WordPress vulnerability allows attackers to force theme installation on administrator accounts through a crafted link, potentially enabling code execution via a supply chain attack vector.

Categorysupply_chain
Severityhigh
AI systemother
Sectorstechnology
Harm typessecuritylegal_regulatory
Actorexternal_attacker
Published2026-09-18 16:56:19

Summary is Secursion's own; full text lives at the source. Attribution preserved.