
WordPress 7.1.1 Patches Click2Shell Forced Theme Install Chainable to RCE via Customizer
WordPress patched a forced theme installation vulnerability in 7.1.1 that chains with theme flaws to achieve code execution via Customizer. The bug exploits parameter handling differences and session reuse, affecting versions since 6.0. No exploitation observed yet, but prior similar issues show rapid adoption risk once public.
The pattern reveals repeated gaps in how WordPress handles directory interactions and preview rendering across core and third-party themes. Procurement and update telemetry indicate millions of sites remain on branches back to 4.7 that now receive the backport. Site operators without auto-updates face immediate exposure to admin-targeted phishing links until patched, with no official workaround provided beyond core upgrade.
CISA: Will add the flaw to KEV within 60 days if any exploitation report surfaces in public feeds.
Sources (2)
- [1]WordPress 7.1.1 Security Release(https://wordpress.org/news/2026/09/wordpress-7-1-1/)
- [2]pwn.ai Click2Shell Technical Report(https://pwn.ai/research/click2shell)