#Click2Shell
WordPress 7.1.1へ更新済みでもCVE-2026-87902の修正は入っていません。
これはClick2Shellとは別の問題で、未ログインの第三者が細工したpagenameを送るとテーマの構造など条件次第でテーマ外のPHPファイルを読み込ませられます。
7.1系は7.1.2、旧系列は対応する修正版を確認してください。
https://chunlog.jp/wordpress-7-1-2-cve-2026-87902/?utm_source=bluesky&utm_medium=social&utm_campaign=post
#WordPress #セキュリティ
WordPress 7.1.2の脆弱性CVE-2026-87902とは?悪用状況と更新手順
WordPress 7.1.2で修正されたCVE-2026-87902とは。未ログインで試みられる攻撃の仕組みと観測状況、旧バージョン系列を含む修正版の確認方法、更新後に調べたい痕跡を解説します。
chunlog.jp
September 26, 2026 at 10:06 AM
WordPressのClick2Shellは、管理者がログイン中に細工されたリンクを開くと、公式ディレクトリのテーマが意図せずインストールされる問題です。テーマは有効化されないため、サイトの見た目だけでは気づけません。更新後も「外観」→「テーマ」で覚えのないテーマを確認してください。コード実行にはテーマ側の別の脆弱性も必要です。

https://chunlog.jp/wordpress-click2shell/?utm_source=bluesky&utm_medium=social&utm_campaign=post
#WordPress #Click2Shell
WordPressのClick2Shell脆弱性とは?7.1.1の修正内容と影響
WordPressのClick2Shellはログイン中の管理者に細工されたリンクを開かせテーマを自動インストールさせる脆弱性です。コード実行に必要な追加条件、7.1.1での修正と現在入れるべき7.1.2、更新後の確認先を整理します。
chunlog.jp
September 24, 2026 at 11:02 PM
🐧 **WordPress 7.1.2 Release, Patches ‘Click2Shell’ Vulnerability**

new from WordPress

📰 Source: Tux Machines
🔗 Link: https://tuxmachines.org/n/2026/09/23/WordPress_7_1_2_Release_Patches_Click2Shell_Vulnerability.shtml
WordPress 7.1.2 Release, Patches ‘Click2Shell’ Vulnerability
new from WordPress
tuxmachines.org
September 24, 2026 at 6:07 PM
WordPress 7.1.2 Release, Patches ‘Click2Shell’ Vulnerability
new from WordPress
tuxmachines.org
September 23, 2026 at 7:41 PM
Vous gérez un site WordPress ? Un simple lien piégé peut permettre de le pirater siecledigital.fr/2026/09/21/v...
Vous gérez un site WordPress ? Un simple lien piégé peut permettre de le pirater
La faille, baptisée Click2Shell par les chercheurs de pwn.ai, devient bien plus dangereuse lorsqu'elle est combinée à une seconde vulnérabilité présente dans un thème WordPress. Un administrateur peut...
siecledigital.fr
September 23, 2026 at 7:01 PM
If you stopped at Click2Shell / 7.1.1, you are not done.

CVE-2026-87902 is unauth LFI in core template resolution. Patchstack saw probes the same day.

Update to 7.1.2 or your backport. Hunt logs for odd pagename + page_id.

Already patched? Drop a ✅. Agency life? Pass it to your clients.
September 23, 2026 at 1:33 PM
WordPress Click2Shell flaw lets hackers execute PHP on the server

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]
#hackernews #news
WordPress Click2Shell flaw lets hackers execute PHP on the server
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]
www.bleepingcomputer.com
September 22, 2026 at 7:05 PM
Crucial info! WordPress users, update now. 'Click2Shell' is a serious RCE threat via theme installs. Prioritize patching! #WordPressSecurity
September 22, 2026 at 6:06 PM
🖲️ #Noticia #CiberSeguridad #Cybersecurity #CiberNoticia

Vulnerabilidad "Click2Shell" en WordPress fuerza la instalación de temas y puede encadenarse para lograr la ejecución de código

Leer Más / Read More...
Vulnerabilidad "Click2Shell" en WordPress fuerza la instalación de temas y puede encadenarse para lograr la ejecución de código
Haz clic para acceder al contenido completo.
blog.segu-info.com.ar
September 22, 2026 at 5:44 PM
🛑 Click2Shell : une faille dans WordPress permet d’exécuter du code PHP en un clic

Un clic sur un lien piégé qui peut coûter cher si on est connecté en tant qu'admin à son #WordPress.

Plus d'infos par ici :
- www.it-connect.fr/wordpress-cl...
September 22, 2026 at 3:13 PM
Sicherheitsupdates: Click2Shell-Lücke zum Kompromittieren von WordPress-Websites | Security www.heise.de/news/Sicherh...
Sicherheitsupdates: Click2Shell-Lücke zum Kompromittieren von WordPress-Websites
Aufgrund mehrerer Sicherheitslücken raten die WordPress-Entwickler zu einem zügigen Update. Bislang gibt es keine Hinweise auf Attacken.
www.heise.de
September 22, 2026 at 2:20 PM
WordPress 7.1.1 (17 Sep) patched Click2Shell and Comment2Shell (CVE-2026-93485). Public PoCs and mainstream write-ups landed 21–22 Sep.

Agency checklist:
1) Confirm every install is on 7.1.1 or your branch’s security backport
2) Check inactive themes you did not expect
3) Tighten comment moderation
September 22, 2026 at 1:44 PM
WordPress 7.1.1 patches 11 flaws, including Click2Shell, a vulnerability that could let attackers force a theme install via malicious preview URLs and potentially run PHP code on the server. #WordPress #Click2Shell #pwnai
WordPress Patches ‘Click2Shell’ Vulnerability
WordPress patched 11 vulnerabilities last week, including Click2Shell, a flaw that could allow remote code execution through specially crafted theme-preview URLs. pwn.ai found that an unauthenticated attacker could force installation of an attacker-selected theme and potentially execute PHP code on the server, earning a $300 bug bounty for the report. #Click2Shell...
www.hendryadrian.com
September 22, 2026 at 12:45 PM
WordPress patched the CRITICAL Click2Shell flaw (v4.7 – 7.1.0). Attackers could trigger remote code execution via inactive theme previews. Update to 7.1.1 or apply security backports immediately. https://radar.offseq.com/threat/wordpress-patches-click2shell-vulnerability-f550dfa1d978a913 #OffSeq ...
WordPress Patches ‘Click2Shell’ Vulnerability
The Click2Shell vulnerability in WordPress arises from inconsistent interpretation of a value in the theme-preview URL by the themes API and the JavaScript running in an administrator's browser. The API reduces the value to a standard theme
radar.offseq.com
September 22, 2026 at 12:00 PM
🤬 WordPress security flaw lets hackers run PHP code on servers. Like the Equifax breach, but this time it's a plugin— stay updated and patched. https://gigcitygeek.com/211127
WordPress Click2Shell flaw lets hackers execute PHP on the server
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed
gigcitygeek.com
September 22, 2026 at 11:54 AM
WordPressの「Click2Shell」脆弱性により、攻撃者はテーマの自動インストール・プレビューが可能になり、リモートコード実行に繋がる恐れがあります。
WordPress Patches 'Click2Shell' Vulnerability
WordPress has patched Click2Shell, a vulnerability that allows attackers to install themes and achieve remote code execution.
www.securityweek.com
September 22, 2026 at 11:29 AM