Security Feed
  1. Archives

Sep 21 2026 WordPress Click2Shell flaw lets hackers execute PHP on the server

Source

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]

Posted by Bill Toulas on Mon 21 September 2026 in BleepingComputer.

Tags: Security.

Categories

  1. Ars Technica
  2. AWS Security
  3. BleepingComputer
  4. Brian Krebs
  5. Bruce Schneier
  6. GCP Security
  7. Google Project Zero
  8. The Daily Swig
  9. The Guardian
  10. The Register
  11. Threatpost

Tag cloud

  • Security
  • Uncategorized
  • Security, Identity, & Compliance
  • Security Blog
  • Biz & IT
  • Microsoft
  • AI
  • Security & Identity
  • Artificial Intelligence
  • Announcements
  • CryptoCurrency
  • Google
  • Foundational (100)
  • Legal
  • privacy
  • A Little Sunshine
  • Apple
  • Advanced (300)
  • LLM
  • Intermediate (200)
  • Hacking
  • Technical How-to
  • squid
  • Mobile
  • vulnerabilities

Security Feed. Powered by Pelican and m.css. Code is available on GitLab.