WordPress Click2Shell CSRF flaw enables remote code execution
A critical cross-site request forgery vulnerability in WordPress Core, dubbed Click2Shell, allows attackers to execute arbitrary PHP code on affected servers. Technical details and proof-of-concept exploits were published on 2026-09-21.