WordPress Click2Shell flaw lets hackers execute PHP on the server
Executive Summary
A new WordPress Core vulnerability, dubbed Click2Shell, is a cross‑site request forgery (CSRF) flaw that allows attackers to execute arbitrary PHP code on the server. The flaw can be triggered by crafted requests and a proof‑of‑concept exploit has been released, enabling remote code execution without authentication.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-21T18:23:11+00:00 - Category: threat-intel
Original Description: Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]
"Wisdom is the supreme part of happiness."
— Sophocles
Source: Bleeping Computer