:

WORDPRESS CLICK2SHELL FLAW ALLOWS PHP EXECUTION

SECURITY DESK1 MIN READ
TUE, SEP 22, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A cross-site request forgery (CSRF) vulnerability in WordPress Core, dubbed 'Click2Shell,' enables attackers to execute PHP code on vulnerable servers. Technical details and working exploits are now public.

The Click2Shell flaw affects WordPress's core functionality, allowing remote code execution through CSRF attacks. Attackers can trick site administrators into visiting a malicious page, which then executes arbitrary PHP commands on the server. Security researchers have released proof-of-concept exploits alongside technical documentation, increasing the risk of widespread attacks. The vulnerability's public disclosure means threat actors can immediately begin targeting unpatched installations. WordPress users should prioritize updating to the latest patched version. Site administrators running older versions face elevated risk of compromise, potentially leading to complete server takeover. CSRF vulnerabilities typically require social engineering to succeed, but when combined with PHP execution capabilities, they pose severe threats. Organizations managing multiple WordPress instances should audit their deployments and apply security patches immediately.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The ShinyHunters extortion group took control of the dark web leak site belonging to the prolific Cl0p ransomware gang over the weekend. The attackers set an eight-figure extortion demand pegged at 2.333% of Cl0p's estimated net worth.

3H AGOSecurity Desk

The FBI's CJIS Security Policy v6.1 strengthens encryption requirements and vulnerability scanning mandates. Agencies must prepare for updated password, MFA, and identity verification standards ahead of compliance audits.

5H AGOSecurity Desk

New research reveals that digital watermarks intended to protect content ownership are being repurposed as surveillance mechanisms to track user behavior and identify individuals across platforms.

5H AGOIndustry Desk

Donating or recycling an old laptop is environmentally responsible, but failing to erase your data first can expose personal information to new owners or data recovery specialists.

8H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.