Click2Shell: One Link Could Give Hackers Your WordPress Site
Good morning. Here are the five WordPress security stories worth knowing about today.
First up, we’ve got an important update to the WordPress 7.1.1 story. Researchers have now published the full attack chain behind one of the fixes, and they’ve called it Click2Shell. A logged-in WordPress administrator only needs to open a malicious link.
WordPress can be tricked into installing a theme without the administrator clicking install, and researchers demonstrated how that can be chained into code execution on the server. There are no confirmed real-world attacks at this stage, but the technical details are now public.
The fix is already in WordPress 7.1.1, so the action hasn’t changed. Update WordPress to 7.1.1 and verify the update completed, because now we understand why the update matters.
Next up, there’s a new vulnerability in NextGEN Gallery, a plugin running on more than 300,000 WordPress sites. The problem is in its zip import feature. A user who has permission to manage galleries can upload a zip file, but older versions don’t correctly check the files inside it.
That means a dangerous file could be extracted into a public directory on the server, and on some hosting environments, that can become remote code execution. The vulnerability affects versions before 4.5.0. The plugin is already on 4.5.1, so update it to the latest version and only give gallery management access to people who genuinely need it.
Next up is Unlimited Elements for Elementor. This one also affects more than 300,000 sites, and it involves PHP object injection. That sounds technical, but the important bit is this: a low-level WordPress user such as a subscriber can potentially feed dangerous data into the plugin, and under the right conditions, that can lead to server-side code execution.
There was an earlier partial fix, but the issue wasn’t completely resolved until version 2.0.20. So if you use Unlimited Elements, make sure you’re on 2.0.20 or later. And if your site allows public user registration, I’d move this one higher on the list.
Next up, this one matters to agencies. ManageWP Worker, installed on around 1 million WordPress sites, has an authentication bypass vulnerability. The flaw affects versions before 4.9.37.
The problem involves ManageWP’s automatic login links, which don’t properly bind the authorised login to the user account being opened. So if an attacker obtains a valid login link, they may be able to reuse it and gain a session as another WordPress user, potentially even as an administrator.
WPScan scheduled its proof-of-concept disclosure for the 20th of September, so that disclosure window has now arrived. The current ManageWP Worker release is 4.9.38, so if ManageWP is part of your management stack, update the Worker plugin everywhere. For agencies managing dozens or hundreds of sites, this is exactly the kind of vulnerability you don’t want sitting in the fleet.
And finally this morning, there’s a critical vulnerability in Amelia Premium that can allow an unauthenticated attacker to work their way up to WordPress administrator. The vulnerable versions are 8.0 through 9.6.2, so the fix is in 9.6.3.
What makes this worth mentioning today is a new exploitation report saying this vulnerability has been seen in the wild. That report is currently single-source intelligence, and CISA has not added it to its exploited vulnerabilities catalogue, so I wouldn’t call it fully independently confirmed. But with a vulnerability that can end in administrator access, I wouldn’t wait for more confirmation.
If you use Amelia Premium, update it immediately and check your WordPress users for administrator accounts you don’t recognise.
And that’s your WordPress security briefing for today. The big one this morning is the new detail around Click2Shell. WordPress 7.1.1 was already important, and now we know attackers have the technical roadmap.
Then check your sites for NextGEN Gallery, Unlimited Elements, ManageWP Worker and Amelia Premium. Patch what you actually run, verify the update, and where administrator access or code execution was possible, check whether anything happened before you patched.