chiprook
← Security
SecuritySeptember 22, 2026, 01:23

WordPress Click2Shell flaw lets hackers run PHP on the server

Researcher Paulos Yibelo of pwn.ai disclosed Click2Shell, a CSRF vulnerability in WordPress Core that lets an attacker force-install any theme from the WordPress.org catalog and execute arbitrary PHP. The flaw was fixed in WordPress 7.1.1, and exploitation requires a logged-in administrator to visit a crafted URL.

WordPress Click2Shell flaw lets hackers run PHP on the server
#WordPress
Read next
Security

U.S. jails expand continuous biometric monitoring as data rules lag

Security

ZoomEye: Over 239,000 Citrix NetScaler Gateways Exposed Amid SAML Bypass

Security

Microsoft and Google take down $66 million RedVDS cybercrime marketplace

Security

Contagious Interview Campaign Hits 30,000 Devices, Steals $10.71M in Crypto