A recent security flaw in the popular content management system WordPress, known as "Click2Shell," allowed attackers to install malicious themes and execute code on a server with the help of an administrator's credentials. The vulnerability was patched in WordPress version 7.1.1, released on September 17. According to reports, attackers could previously exploit two separate vulnerabilities in the WordPress core to execute code remotely. However, the new flaw requires an administrator to inadvertently open a malicious link, which triggers the installation of a theme chosen by the attacker from the official WordPress repository. The vulnerability was discovered by Paulos Yibelo, a security researcher at pwn.ai, and disclosed to WordPress on August 22. Technical details were made public on September 18. Although the flaw has been known since WordPress 6.0, no actual attacks have been reported, and WordPress plans to assign a CVE identifier to the vulnerability for tracking purposes. The exploitation method involves an attacker crafting a specific URL that points to the theme installation page, /wp-admin/theme-install.php, and inserting special characters into the theme parameter. WordPress.org then interprets this as a request to install an official theme, such as "twentytwenty." The administrator's browser processes the raw URL without escaping the characters, which are then used in a jQuery selector to locate an element on the page. These characters trick the selector into targeting the real "Install" button. The WordPress JavaScript automatically clicks this button and uses the administrator’s security token to install the theme without needing to steal a CSRF token. The installed theme remains inactive and does not alter the website's appearance. The attack requires the administrator to click on the malicious link once, and the attacker can only install themes from the official WordPress.org repository, not arbitrary archives. To escalate the attack to code execution, pwn.ai researchers exploited a feature in WordPress that allows the PHP code of a theme to be loaded during a preview in the Customizer, even if another theme is active. They forced the installation of the Mobile Repair Zone 2.5.4 theme, which was available in the official repository at the time, and then triggered a preview using the address /wp-admin/admin-ajax.php with specific parameters. The theme’s code included an AJAX handler that lacked a security token and proper access controls. The attacker then sent a request to this handler, instructing it to download and execute a malicious plugin. This allowed the attacker to run arbitrary PHP code under the server’s account, effectively taking control of the system. On the CVSS 3.1 scale, the forced installation alone was rated at 7.1, while the complete chain leading to code execution was rated at 9.6, indicating a high-risk vulnerability. pwn.ai provided WordPress with the full exploit details and proof of concept on September 1 and received the maximum reward from the company’s bug bounty program. The WordPress team fixed the issue by modifying the selector to escape the address value and limit the search to the legitimate install button, as seen in changeset 63664. Version 7.1.1 of WordPress includes 11 security fixes, including the vulnerability that allowed specially crafted URLs to automatically install and preview inactive themes. The fix has been backported to all eligible versions, including up to WordPress 4.7. Administrators with automatic background updates enabled will receive the patch automatically, while others can install it manually from their dashboard. The status of the Mobile Repair Zone theme in the repository remains unclear, according to pwn.ai.