Act
active
WordPress Core 'Click2Shell' CSRF flaw enables PHP execution
- Engineer — Act: A public PoC now lowers the exploitation bar for this CSRF-to-PHP-execution flaw in WordPress Core; patch WordPress to the latest patched release and verify that admin-facing endpoints require nonce validation.
- SOC/IR — Plan: No confirmed active exploitation yet, but a public PoC means campaigns are likely imminent; build or tune detections for anomalous PHP execution originating from WordPress admin paths and unexpected file-write activity on web roots.
- Leader — Learn: A meaningful WordPress Core vulnerability with a published exploit — not yet at systemic scale, but worth confirming your engineering team has patched any WordPress instances; no board-level action required unless exploitation becomes widespread.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.