WordPress Click2Shell CSRF flaw enables remote code execution

A critical cross-site request forgery vulnerability in WordPress Core, dubbed Click2Shell, allows attackers to execute arbitrary PHP code on affected servers. Technical details and proof-of-concept exploits were published on 2026-09-21.

3 reportsother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component

mastodon:infosec-exchangeother8d ago kagi ↗

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. https://www. bleepingcomputer.com/news/secu rity/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/