Bleepingcomputer iconBleepingcomputerSep 21, 2026

WordPress Click2Shell flaw lets hackers execute PHP on the server

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component.

WordPress Click2Shell flaw lets hackers execute PHP on the server

Share this story

Send the public story page.

Useful takeaways from this story.

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app