← Back to Feed
WordPress Click2Shell flaw lets hackers execute PHP on the server
September 21, 2026 · BleepingComputer · Severity: HIGH
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component.
Key Takeaways
- WordPress Click2Shell flaw enables attackers to execute PHP code on vulnerable servers through a critical remote code execution vulnerability affecting millions of WordPress installations.
- The ability to execute arbitrary PHP code on WordPress servers gives attackers complete control over affected websites, including data theft, malware injection, and defacement capabilities.
- WordPress site administrators should immediately apply the latest security updates and verify their sites for signs of post-exploitation activity from this vulnerability.