Web Hack List

Preliminary research

Click2Shell: theme-selector injection and preactivation code execution in WordPress

Click2Shell: Preauth WordPress Core Theme Preview Injection to RCE Chain

AI-collected research leads through 24 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

A theme slug is normalized by the catalog API but reused as selector syntax in WordPress admin JavaScript, forcing installation. Customizer loading of an inactive vulnerable catalog theme then exposes an unchecked plugin installer, enabling PHP execution after an administrator follows the crafted link.

Record

Document
Click2Shell: Preauth WordPress Core Theme Preview Injection to RCE Chain
Researcher
PWNAI Research
Published by
pwn.ai
Date
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of PWNAI Research, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .