TechBleepingComputer1h ago
WordPress Click2Shell flaw lets hackers execute PHP on the server

TL;DRWordPress vulnerability lets attackers run malicious code on servers via CSRF attacks.
Why it matters: Core WordPress flaw with public exploit code puts millions of sites at immediate risk.
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]
Read full articleSource: BleepingComputer · Opens in new tab