WordPress Fixes Critical “Click2Shell” Vulnerability
WordPress has released a security update that closes the “Click2Shell” vulnerability, a flaw that allowed attackers to automatically install and preview themes and could lead to remote code execution.
The issue was discovered in the theme preview feature of WordPress core. By sending a specially crafted request, a malicious actor could trigger the installation of a theme without user interaction, then execute arbitrary code on the server. The vulnerability affected all supported versions of WordPress that had not yet applied the patch.
Site owners who run WordPress sites, especially those using the built‑in theme installer, were at risk. The exploit required only a web request, meaning an attacker could target any vulnerable site without needing credentials. Successful exploitation could give the attacker full control over the hosting environment, potentially leading to data theft, defacement, or use of the server for further attacks.
WordPress users should update to the latest version immediately. The update is available through the standard dashboard update mechanism and can also be applied manually by downloading the latest package from wordpress.org. After updating, verify that the theme installer works as expected and review server logs for any unusual activity.
For additional protection, consider using a web‑application firewall such as the free ModSecurity ruleset recommended on ComputerScams.com, and keep all plugins and themes up to date. Regular backups stored off‑site will also help you recover quickly if an intrusion occurs.
The quick fix shows how essential it is to apply security patches without delay. Staying current with updates and employing basic hardening steps remain the most effective defense against such flaws.
A practical step you can take right now is to log into your WordPress admin area and run the pending updates. If you cannot access the dashboard, download the latest WordPress release and follow the manual upgrade guide.
Source: Read the original report