Skip to finding
important · Research / RCE

One WordPress administrator visit can install an inactive theme and execute attacker-supplied PHP.

Affects

WordPress, a web content-management system, chained with the Mobile Repair Zone catalog theme or another theme exposing a comparable pre-activation installer.

A logged-in administrator must open a crafted theme-preview URL, but the attacker needs no WordPress account and the selector injection triggers installation without an Install or Activate click.

Detail and 2 sources

The demonstrated theme then exposes an unauthenticated package installer that fetches an attacker-selected plugin and executes its PHP. WordPress has fixed the forced install-and-preview issue.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 19, 2026