ZeroHour
Product

Mobile Repair Zone

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Click2Shell: The RCE WordPress 7.1.1 Just Patched

WordPress 7.1.1 patches Click2Shell, a CSRF-to-selector-injection chain letting attackers gain remote code execution via crafted links clicked by admins.

WordPress 7.1.1, released 17 September 2026, fixes a chain reported by Paulos Yibelo of pwn.ai that abuses an unsanitized theme slug in wp-admin JavaScript. The slug is injected into a jQuery selector, tricking an admin's browser into installing an attacker-chosen theme; the chain then abuses an AJAX handler in theme Mobile Repair Zone 2.5.4 that lacks nonce and capability checks, allowing a malicious plugin ZIP to be installed and executed server-side for full RCE. Exploitation requires an administrator to load a crafted URL while logged in, or an existing XSS foothold on the site. The fix scopes the selector to real .theme elements and applies $.escapeSelector() before injection.

Patchstack · 3h agoVulnerability 6 sources1· 1 read

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

WordPress 7.1.1 patches Click2Shell, a flaw letting crafted links force-install themes on admin visits, chainable to remote code execution; no exploitation observed.

Researchers at pwn.ai disclosed Click2Shell, a WordPress core flaw where a crafted link, opened by a logged-in administrator, silently installs an attacker-chosen theme from WordPress.org using the admin's own session and security token. The forced install alone is rated CVSS 7.1; chained with an unauthenticated background download handler in the Mobile Repair Zone theme, it reaches CVSS 9.6 remote code execution. WordPress fixed the bug in 7.1.1 released September 17, with fixes backported to supported branches down to 4.7. No CVE has been assigned yet and there is no sign of exploitation, unlike the separate, CISA-listed wp2shell flaw.

The Hacker Newsupdated · 3h agofirst · 5h agoVulnerability 6 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.