> WordPress Click2Shell flaw lets hackers execute PHP on the server
[AUTHOR: Bill Toulas]
[DATE: 21/09/2026 18:23]
[LANGUAGE: EN]
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]