Skip to content
WP Hack FixEst. 2005

Security news

WordPress 7.1.1 fixes 11 security issues, including a one-click site takeover

Published · Disclosed September 17, 2026 · Reviewed by Adam Taylor

WordPress released version 7.1.1 on September 17. It’s a maintenance and security release that fixes 11 security issues in WordPress itself, along with 36 ordinary bugs. Two of the security fixes stand out.

Am I affected?

If your site runs any version of WordPress older than 7.1.1, yes.

To check: log in to your dashboard and look at Dashboard → Updates, or scroll to the bottom right of the dashboard home screen, where the version number is shown.

Most sites update themselves for releases like this one. WordPress installs these automatically unless someone has turned that off, or your host manages updates for you. Automatic doesn’t mean instant, though, and plenty of sites have it disabled without the owner knowing.

The two that matter

A site takeover that only needs an admin to click a link. Researchers at Patchstack found a chain they’ve nicknamed “Click2Shell.” An attacker crafts a link and gets a logged-in administrator to open it. That quietly installs a theme, previews it, and uses a gap in the theme’s own code to run whatever the attacker wants on the server. The admin sees nothing unusual.

The important part for site owners: nobody has to guess your password. It works because your browser is already logged in. A convincing email to whoever runs your site is enough. It was reported responsibly and there’s no public sign it’s being used in the wild yet, which usually changes once the details are out.

A comment can plant a script in your pages (CVE-2026-93485). A flaw in the function WordPress uses to format text let a specially written comment slip past the filters that are supposed to strip dangerous code. Anonymous comments were enough to trigger it, so no account was needed.

The other nine fixes cover a REST API path traversal, a theme installation flaw, private post titles leaking, comment reparenting, and several more.

What to do

  1. Update to 7.1.1. Dashboard → Updates → Update Now. It takes under a minute on most sites.
  2. Check that automatic updates are on if you’d rather not think about this each time.
  3. Take a backup first if your site is heavily customised, as with any update.
  4. Warn whoever else has admin access. With the Click2Shell issue, an admin clicking a link in an email is the whole attack. That’s worth mentioning to your team today.

If your site is on an older release, note that only the current version is actively maintained. The security team has backported these fixes to WordPress 4.7 and later, but staying several versions behind means you’re relying on that goodwill continuing.

On a Protect plan? Core updates are part of what we do, so this is already handled and you don’t need to act.

Not sure if your site updated, or worried something already got in? Ask us and we’ll take a look.

Worried your site's already been hit?

If something looks wrong, we'll check it and clean it up. If we can't fix it, you don't pay.

We reply within 1 business day (Mon–Fri, 9–5 ET)