WordPress Click2Shell flaw lets hackers execute PHP on the server
BLUF
WordPress users face immediate risk from a new CSRF vulnerability enabling remote code execution.
NEWS
Researchers have published technical details and an exploit for the Click2Shell flaw found in WordPress Core. This cross-site request forgery vulnerability allows unauthenticated attackers to execute arbitrary PHP code on the server if a victim interacts with a malicious link.
Why I Care
This matters because it grants full server control to attackers, potentially leading to data theft or site defacement. All WordPress Core users are at risk until patched, as the exploit is publicly available.
Next Steps
Site administrators should update WordPress to the latest version immediately upon release. Monitor logs for suspicious activity and apply web application firewall rules if an update isn't available yet.
Source: BleepingComputer ·