{"id":11951,"date":"2026-09-18T18:00:00","date_gmt":"2026-09-19T00:00:00","guid":{"rendered":"https:\/\/beaconlab.us\/publicacion\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/"},"modified":"2026-09-29T09:59:06","modified_gmt":"2026-09-29T15:59:06","slug":"alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce","status":"publish","type":"publicacion","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/","title":{"rendered":"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Affected product(s):<\/h2>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Product<\/strong><\/td><td><strong>Affected versions<\/strong><\/td><td><strong>Fixed version<\/strong><\/td><\/tr><tr><td><strong>WordPress Core<\/strong><\/td><td>WordPress 6.0 up to versions prior to the corresponding security patch<\/td><td>WordPress 7.1.1 or equivalent security update for the supported branch<\/td><\/tr><tr><td><strong>WordPress Core \u2014 older branches with security support<\/strong><\/td><td>Supported versions since WordPress 4.7 affected by the issue<\/td><td>Maintenance\/security update published on September 17, 2026<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<p class=\"has-small-font-size wp-block-paragraph\">* WordPress confirmed that the issue is present from version <strong>6.0<\/strong> up to versions immediately preceding the fix. The security update of September 17, 2026 includes fixes for supported branches since WordPress 4.7<\/p>\n\n<h2 class=\"wp-block-heading\">Description<\/h2>\n\n<p class=\"wp-block-paragraph\">A vulnerability was identified in the WordPress core that allows a specially crafted URL to force the installation and preview of a legitimate theme from the WordPress.org repository when an authenticated administrator opens the link. The vulnerability, named <strong>Click2Shell<\/strong>, was fixed in <strong>WordPress 7.1.1<\/strong> and in the equivalent updates for supported branches. There is no CVE published yet, but a score of 9.6 (critical) is estimated.<\/p>\n\n<p class=\"wp-block-paragraph\">Click2Shell is a URL-induced forced theme installation vulnerability. The issue occurs because two WordPress components interpret a parameter included in a manipulated URL differently: the WordPress.org repository interprets it as the normal name of a valid theme, while the administrator&#8217;s browser reuses the original content \u2014including additional characters\u2014 within JavaScript code used to locate an element on the page.<\/p>\n\n<p class=\"wp-block-paragraph\">The use of specially prepared characters allows the browser selector to point to the <strong>Install<\/strong> button and the WordPress script itself to execute the installation action. Since the administrator already has an active session, the browser automatically includes their permissions and security token (<em>nonce<\/em>), so the attacker does not need to know credentials or obtain that token.<\/p>\n\n<p class=\"wp-block-paragraph\">Click2Shell should not be confused with <strong>wp2shell<\/strong>, another WordPress Core vulnerability disclosed in July 2026. wp2shell does not require login or user interaction, and CISA included it as an actively exploited vulnerability; Click2Shell, on the other hand, requires an authenticated administrator to open a specially crafted link and has no known active exploitation.<\/p>\n\n<h2 class=\"wp-block-heading\">Solution<\/h2>\n\n<p class=\"wp-block-paragraph\">The official solution is to update WordPress to <strong>7.1.1<\/strong> or to the security update published for the corresponding supported branch. The update can be performed from the administration panel at <strong>Dashboard &gt; Updates &gt; Update Now<\/strong>, or via the installation package available from WordPress.org.<\/p>\n\n<p class=\"wp-block-paragraph\">There is no standalone <em>workaround<\/em> that eliminates the URL interpretation flaw. Disabling themes, restricting the administration panel, and avoiding suspicious links are temporary controls that reduce the likelihood of exploitation, but they do not replace applying the patch.<\/p>\n\n<p class=\"wp-block-paragraph\">After updating, it is recommended to keep only necessary themes and plugins, apply security updates promptly, and use additional controls to protect administrative sessions.<\/p>\n\n<h2 class=\"wp-block-heading\">Additional information:<\/h2>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/wordpress.org\/news\/2026\/09\/wordpress-7-1-1-maintenance-and-security-release\/\" target=\"_blank\" rel=\"noopener\">https:\/\/wordpress.org\/news\/2026\/09\/wordpress-7-1-1-maintenance-and-security-release\/<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-1-1\/\" target=\"_blank\" rel=\"noopener\">https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-1-1\/<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/thehackernews.com\/2026\/09\/new-wordpress-click2shell-flaw-forces.html\" target=\"_blank\" rel=\"noopener\">https:\/\/thehackernews.com\/2026\/09\/new-wordpress-click2shell-flaw-forces.html<\/a><\/li>\n<\/ul>\n","protected":false},"featured_media":11614,"template":"","class_list":["post-11951","publicacion","type-publicacion","status-publish","has-post-thumbnail","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Affected product(s): * WordPress confirmed that the issue is present from version 6.0 up to versions immediately preceding the fix. The security update of September 17, 2026 includes fixes for supported branches since WordPress 4.7 Description A vulnerability was identified in the WordPress core that allows a specially crafted URL to force the installation and\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"Affected product(s): * WordPress confirmed that the issue is present from version 6.0 up to versions immediately preceding the fix. The security update of September 17, 2026 includes fixes for supported branches since WordPress 4.7 Description A vulnerability was identified in the WordPress core that allows a specially crafted URL to force the installation and\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-19T00:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-29T15:59:06+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Affected product(s): * WordPress confirmed that the issue is present from version 6.0 up to versions immediately preceding the fix. The security update of September 17, 2026 includes fixes for supported branches since WordPress 4.7 Description A vulnerability was identified in the WordPress core that allows a specially crafted URL to force the installation and\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\\\/#listItem\",\"name\":\"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\\\/#listItem\",\"position\":2,\"name\":\"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\\\/\",\"name\":\"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE - Beacon Lab\",\"description\":\"Affected product(s): * WordPress confirmed that the issue is present from version 6.0 up to versions immediately preceding the fix. The security update of September 17, 2026 includes fixes for supported branches since WordPress 4.7 Description A vulnerability was identified in the WordPress core that allows a specially crafted URL to force the installation and\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\\\/#breadcrumblist\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/WordPress-logotype-wmark.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\\\/#mainImage\",\"width\":1000,\"height\":1000},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\\\/#mainImage\"},\"datePublished\":\"2026-09-18T18:00:00-06:00\",\"dateModified\":\"2026-09-29T09:59:06-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE - Beacon Lab","description":"Affected product(s): * WordPress confirmed that the issue is present from version 6.0 up to versions immediately preceding the fix. The security update of September 17, 2026 includes fixes for supported branches since WordPress 4.7 Description A vulnerability was identified in the WordPress core that allows a specially crafted URL to force the installation and","canonical_url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/#listItem","name":"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/#listItem","position":2,"name":"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/#webpage","url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/","name":"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE - Beacon Lab","description":"Affected product(s): * WordPress confirmed that the issue is present from version 6.0 up to versions immediately preceding the fix. The security update of September 17, 2026 includes fixes for supported branches since WordPress 4.7 Description A vulnerability was identified in the WordPress core that allows a specially crafted URL to force the installation and","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/#breadcrumblist"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/#mainImage","width":1000,"height":1000},"primaryImageOfPage":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/#mainImage"},"datePublished":"2026-09-18T18:00:00-06:00","dateModified":"2026-09-29T09:59:06-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE - Beacon Lab","og:description":"Affected product(s): * WordPress confirmed that the issue is present from version 6.0 up to versions immediately preceding the fix. The security update of September 17, 2026 includes fixes for supported branches since WordPress 4.7 Description A vulnerability was identified in the WordPress core that allows a specially crafted URL to force the installation and","og:url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/","og:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png","og:image:secure_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png","og:image:width":1000,"og:image:height":1000,"article:published_time":"2026-09-19T00:00:00+00:00","article:modified_time":"2026-09-29T15:59:06+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE - Beacon Lab","twitter:description":"Affected product(s): * WordPress confirmed that the issue is present from version 6.0 up to versions immediately preceding the fix. The security update of September 17, 2026 includes fixes for supported branches since WordPress 4.7 Description A vulnerability was identified in the WordPress core that allows a specially crafted URL to force the installation and","twitter:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/07\/WordPress-logotype-wmark.png"},"aioseo_meta_data":{"post_id":"11951","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-29 15:59:06","updated":"2026-09-29 16:38:56","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAlert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Alert 2026-103 Click2Shell in WordPress allows forced theme installation and can be chained to RCE","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-103-click2shell-in-wordpress-allows-forced-theme-installation-and-can-be-chained-to-rce\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11951","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/publicacion"}],"version-history":[{"count":1,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11951\/revisions"}],"predecessor-version":[{"id":11952,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11951\/revisions\/11952"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media\/11614"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=11951"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}