Home / Sep 22, 2026 / Story
0
#8 BleepingComputer general September 21, 2026 at 18:23 UTC

WordPress Click2Shell flaw lets hackers execute PHP on the server

By Bill Toulas

AI Summary

A proof-of-concept exploit has been published for 'Click2Shell,' a CSRF vulnerability in WordPress Core that allows an attacker to achieve server-side PHP code execution by tricking an authenticated administrator into visiting a malicious page. With a working PoC now publicly available, the exploitation window for unpatched WordPress installations narrows significantly. WordPress site administrators should apply the relevant patch immediately, especially those running internet-exposed admin panels.

Relevance score: 83.0/100

# More from September 22