WordPress has patched Click2Shell, that could allow an attacker to silently install a theme and execute PHP code on the targeted website.