Back to all news
Security

WordPress Click2Shell flaw lets hackers execute PHP on the server

BleepingComputer·September 21, 2026·1 min read
WordPress Click2Shell flaw lets hackers execute PHP on the server

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. The flaw allows hackers to execute PHP on the server, posing a critical risk to unpatched sites.

Read at BleepingComputer
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store