SecurityUnverified

WordPress Click2Shell flaw lets hackers execute PHP on the server

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]

What happened

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]

Why it matters

The incident may affect operational continuity, asset safety or trust around Security. Watch for verified scope and remediation.

Affected entities

View evidence

1 reports · 1 original report · 1 independent

  1. BleepingComputerPrimary source · Supports · EN · 100%
    WordPress Click2Shell flaw lets hackers execute PHP on the server

Claims

  • WordPress Click2Shell flaw lets hackers execute PHP on the server Observed

Conflicts

No material conflict detected in the available evidence.

Timeline

  1. First reported

Market move following event

Market reaction is not yet available for this asset and time window.

Score explanation

Confidence · formula confidence-2.1.0
Source trust84
Independent corroboration51
Primary evidence35
Claim consistency82
Extraction confidence82
Attribution quality90
Impact · formula impact-2.1.0
Event magnitude96
Market relevance74
Entity significance42
Market breadth45
Novelty68
Urgency96
Ranking · formula rank-1.0.0
Confidence factor0.847
Freshness factor0.9998
Breaking bonus8