#8
BleepingComputer
general
September 21, 2026 at 18:23 UTC
WordPress Click2Shell flaw lets hackers execute PHP on the server
By Bill Toulas
AI Summary
A proof-of-concept exploit has been published for 'Click2Shell,' a CSRF vulnerability in WordPress Core that allows an attacker to achieve server-side PHP code execution by tricking an authenticated administrator into visiting a malicious page. With a working PoC now publicly available, the exploitation window for unpatched WordPress installations narrows significantly. WordPress site administrators should apply the relevant patch immediately, especially those running internet-exposed admin panels.
Relevance score: 83.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →