Skip to main content
CyberSingle-sourceMediumDeveloping
4.8

WordPress Click2Shell CSRF flaw allows PHP execution; PoC published

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' affecting the platform's Core component. The flaw could allow attackers to execute arbitrary PHP code on the server, potentially leading to full site compromise. The severity and patch status are not yet fully clear, but the public availability of a PoC increases the risk of exploitation.

BleepingComputer1 day agoengCredibility 24%View source

Score Breakdown

Mosaic Score4.8
Confidence0.5
Significance0.5
Source credibility0.2
Source

Related signals

4 found