One WordPress administrator visit can install an inactive theme and execute attacker-supplied PHP.
WordPress, a web content-management system, chained with the Mobile Repair Zone catalog theme or another theme exposing a comparable pre-activation installer.
A logged-in administrator must open a crafted theme-preview URL, but the attacker needs no WordPress account and the selector injection triggers installation without an Install or Activate click.
Detail and 2 sources
The demonstrated theme then exposes an unauthenticated package installer that fetches an attacker-selected plugin and executes its PHP. WordPress has fixed the forced install-and-preview issue.