CuraSec

Act active

WordPress Core 'Click2Shell' CSRF flaw enables PHP execution

2026-09-22 15:30 UTC · BleepingComputer · read the source ↗ #wordpress#csrf#rce
  • Engineer — Act: A public PoC now lowers the exploitation bar for this CSRF-to-PHP-execution flaw in WordPress Core; patch WordPress to the latest patched release and verify that admin-facing endpoints require nonce validation.
  • SOC/IR — Plan: No confirmed active exploitation yet, but a public PoC means campaigns are likely imminent; build or tune detections for anomalous PHP execution originating from WordPress admin paths and unexpected file-write activity on web roots.
  • Leader — Learn: A meaningful WordPress Core vulnerability with a published exploit — not yet at systemic scale, but worth confirming your engineering team has patched any WordPress instances; no board-level action required unless exploitation becomes widespread.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.