← Back to Feed

WordPress Click2Shell flaw lets hackers execute PHP on the server

September 21, 2026 · BleepingComputer · Severity: HIGH

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component.

Key Takeaways

  • WordPress Click2Shell flaw enables attackers to execute PHP code on vulnerable servers through a critical remote code execution vulnerability affecting millions of WordPress installations.
  • The ability to execute arbitrary PHP code on WordPress servers gives attackers complete control over affected websites, including data theft, malware injection, and defacement capabilities.
  • WordPress site administrators should immediately apply the latest security updates and verify their sites for signs of post-exploitation activity from this vulnerability.
☕ Buy a Coffee