Stuart Neal
Director of Operations at Nextgen Marketing
We have worked with Vitalli and his team for well over a year now and will continue to do so in the future.
Having the confidence in an agency that allowed us to scale up and down development resources, as and when needed, has really made a positive difference to our agency.
Home / Blog / News / Click2Shell: the WordPress attack chain that turned one admin click into a remote shell
Security researcher Paulos Yibelo of pwn.ai reported a vulnerability, named Click2Shell, that chains together CSRF and a JavaScript sanitization mismatch to turn a single administrator click into full remote code execution (per Patchstack’s writeup). It was fixed in WordPress 7.1.1, released September 17 — the kind of fix proactive WordPress security maintenance is built to apply the day it ships, not weeks later.
If you’re on one of our maintenance plans, this fix is already applied and logged in your monthly maintenance report — you don’t need to do anything about Click2Shell specifically. What’s genuinely worth doing regardless of your update status: a quick reminder to your team not to click unexpected links inside wp-admin, since that’s the actual trigger here. If you’re not on a maintenance plan, this is the kind of vulnerability that’s easy to miss precisely because the fix ships quietly inside a routine-looking release.
Source: Patchstack