Preliminary research
Click2Shell: theme-selector injection and preactivation code execution in WordPress
Click2Shell: Preauth WordPress Core Theme Preview Injection to RCE Chain
AI-collected research leads through 24 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
A theme slug is normalized by the catalog API but reused as selector syntax in WordPress admin JavaScript, forcing installation. Customizer loading of an inactive vulnerable catalog theme then exposes an unchecked plugin installer, enabling PHP execution after an administrator follows the crafted link.
Record
- Document
- Click2Shell: Preauth WordPress Core Theme Preview Injection to RCE Chain
- Researcher
- PWNAI Research
- Published by
- pwn.ai
- Date
- Topic
- Injection
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of PWNAI Research, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .