Tuesday, 22 September 2026

Search
Latent Digest

TECHNOLOGY, TRACKED ACROSS DISCIPLINES

Security & Privacy

WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code

A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.

· 1 min read · 1 source

Technical details and a proof-of-concept exploit have been published for a WordPress vulnerability dubbed Click2Shell. The flaw is a cross-site request forgery (CSRF) issue in the platform's Core component, according to BleepingComputer.

Using the vulnerability, attackers can execute PHP on the server. Because the proof-of-concept is now public, the report highlights a concrete exploitation route for what is otherwise a server-side code execution risk.

The report does not mention a patch or official response from WordPress. With the flaw residing in Core, the potential impact is broad, though the source does not provide details on affected versions or mitigation steps.

Source

  1. 01WordPress Click2Shell flaw lets hackers execute PHP on the serverBleepingComputer

More in Security & Privacy