WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Technical details and a proof-of-concept exploit have been published for a WordPress vulnerability dubbed Click2Shell. The flaw is a cross-site request forgery (CSRF) issue in the platform's Core component, according to BleepingComputer.
Using the vulnerability, attackers can execute PHP on the server. Because the proof-of-concept is now public, the report highlights a concrete exploitation route for what is otherwise a server-side code execution risk.
The report does not mention a patch or official response from WordPress. With the flaw residing in Core, the potential impact is broad, though the source does not provide details on affected versions or mitigation steps.
More in Security & Privacy
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.
Google Fined €403 Million by Irish DPC Over Location Data
The penalty targets Google's GDPR breaches in handling user location data and includes a six-month compliance order.