WordPress 7.1.1 patches Click2Shell and Comment2Shell
WordPress 7.1.1 fixes admin-triggered Click2Shell and Comment2Shell XSS CVE-2026-93485; no active exploitation is reported.
WordPress 7.1.1, released September 17, 2026, patches Click2Shell, a core theme-preview flaw in 7.1.0 and earlier that pwn.ai researcher Paulos Yibelo disclosed with a public proof of concept and, according to multiple outlets, no CVE. A logged-in administrator who opens a crafted link can be made to install a WordPress.org theme without an attacker account or install nonce; PHP may then run during Customizer preview. SecurityWeek says more than 40 inactive themes can do so, while GBHackers describes a chain through Mobile Repair Zone 2.5.4. Author and Editor roles cannot trigger it; 7.1.1 escapes the theme slug and restricts the selector, fixes were backported through the 4.7 line, Patchstack says DISALLOW_FILE_MODS blocks forced installs, and the bounty was $300. Separately, Comment2Shell (CVE-2026-93485, CVSS 7.1) is unauthenticated stored XSS in wpautop() from 4.7 through 7.1.0, fixed in 7.1.1 and builds back to 4.7.36, with a public proof of concept that uses an administrator viewing a comment to install a plugin. Sources agree neither issue had confirmed active exploitation; The Hacker News conflates the flaws and mentions wp2shell, which the other reports do not describe, and SecurityWeek says the release fixes 11 vulnerabilities.
- WordPress 7.1.1, released September 17, 2026, fixes Click2Shell in core 7.1.0 and earlier; sources that discuss it say no CVE was assigned, and SecurityWeek says fixes were backported through WordPress 4.7.
- Click2Shell needs a logged-in administrator to open a crafted link; the attacker needs no WordPress account or install nonce, and BleepingComputer says Author and Editor roles cannot trigger it.
- pwn.ai researcher Paulos Yibelo published a proof of concept and received a $300 bounty; SecurityWeek says more than 40 inactive themes can run PHP during Customizer preview, while GBHackers describes a chain through Mobile Repair Zone…
- BleepingComputer says 7.1.1 escapes the theme slug and restricts the selector, and that DISALLOW_FILE_MODS blocks forced theme or plugin installation.
- Comment2Shell is CVE-2026-93485, unauthenticated stored XSS in wpautop(), scored CVSS 7.1, affecting WordPress 4.7 through 7.1.0 and fixed in 7.1.1 plus builds back to 4.7.36.
- Comment2Shell requires comments to be enabled and a privileged user to view the post; a public proof of concept can use that admin session to install a plugin.
- No report described confirmed in-the-wild exploitation. SecurityWeek says 7.1.1 fixes 11 vulnerabilities; The Hacker News conflates the two flaws and also mentions wp2shell.
Coverage timelineoldest first · each row is one article
- · 6d agoClick2Shell WordPress Flaw Lets Hackers Execute PHP Code and Take Over Websites
GBHackers· 62
WordPress 7.1.1 patches Click2Shell, which can force theme installs and enable PHP code execution.
- · 5d agoClick2Shell: WordPress Flaw Enables RCE Chain
SOCRadar· 58
SOCRadar describes Click2Shell, a WordPress Core flaw that can chain a tricked admin browser into RCE.
- · 5d agoWordPress Click2Shell flaw lets hackers execute PHP on the server
BleepingComputer· 78
Public PoC shows WordPress Click2Shell can run PHP if an administrator opens a crafted link.
Vulnerabilities in this storyAll →
- CVE-2026-934857.1<1%Unauthenticated Stored DOM-Based XSS in WordPress Core Affecting 4.7–7.0published · Automattic WordPress (core) PoC ×3
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-93485 | Unauthenticated Stored DOM-Based XSS in WordPress Core Affecting 4.7–7.0 |