A cross-site request forgery (CSRF) vulnerability in WordPress Core, identified as Click2Shell, has been disclosed alongside a proof-of-concept exploit. The flaw allows unauthenticated attackers to execute arbitrary PHP code on affected servers by tricking authenticated users into visiting a malicious link or page.
What happened
Security researchers published technical details and a functional exploit for Click2Shell, a CSRF vulnerability in WordPress Core. The issue enables attackers to bypass authentication requirements and execute server-side PHP code if they can induce an authenticated WordPress user to click a crafted link. The vulnerability affects default WordPress installations and does not require additional plugins or themes to be present.
The proof-of-concept exploit demonstrates how the flaw can be weaponized, though no active exploitation has been reported at this time. The disclosure includes step-by-step instructions for reproducing the attack, which security teams can use to test their own environments.
What we don't know yet
The sources did not specify whether WordPress has released or plans to release an official patch for the vulnerability. No timeline for remediation was provided, nor were details about potential workarounds or mitigations shared. It remains unclear how many WordPress sites may be exposed to this flaw, as usage statistics for specific Core versions were not disclosed.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 21 Sep 2026. First draft failed editor review; a revised version was approved (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 2 candidates
- Checking for duplicates — New story No recent or in-pipeline article covers this WordPress CSRF vulnerability.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers this WordPress CSRF vulnerability.
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=581 slug=wordpress-core-csrf-flaw-enables-php-execution quick_read=1
-
Editor review — Rejected
- Score: 65/100
- Factual grounding: The draft states the disclosure and proof-of-concept were published 'on Monday' without confirming this date aligns with the source publication date (21 September 2026). The source does not explicitly state the disclosure occurred on the same day as publication, only that details were published 'today' (relative to the source's publication date). This is a material ambiguity in timing.
- Factual grounding: The draft claims 'WordPress has not yet issued an official patch or advisory,' but the source does not confirm whether WordPress was notified or has responded. This is an unsupported claim and materially misleading.
- Factual grounding: The draft states 'No evidence suggests the flaw has been exploited in the wild,' but the source does not address exploitation status. This is an unsupported claim and materially speculative.
- Style compliance: The standfirst ('Click2Shell vulnerability in WordPress Core allows unauthenticated PHP code execution') is factual but exceeds the 90-character headline limit (98 characters).
- Audience relevance and notability: The story is relevant to hosting/DNS/email professionals, but the lack of version specificity, patch timeline, or mitigation guidance limits actionable value. This is a minor issue given the severity of the vulnerability.
- Sanity: The draft omits the CVE identifier or other formal tracking details, which are standard for vulnerability disclosures. While not material, this reduces utility for professionals.
- Writing the article — Rewritten editor-driven rewrite
-
Editor review — Approved
- Score: 85/100
- Factual grounding: No confirmation in the source that the vulnerability is named 'Click2Shell' by WordPress Core or security researchers
- the term appears only in the BleepingComputer headline and may be media shorthand. The draft should clarify the naming source or avoid presenting it as an official designation.
- Style compliance: Standfirst ('Click2Shell vulnerability in WordPress Core allows server-side code execution') echoes the title too closely. Standfirst should rephrase to avoid redundancy.
- Style compliance: Section heading 'What we don't know yet' is not one of the allowed section headings (e.g., 'What happened', 'Why it matters', 'What to watch'). Replace with an approved heading like 'What to watch'.
- Audience relevance and notability: No material issue, but the draft could strengthen relevance by explicitly noting the vulnerability's impact on hosting providers, domain registrars, or email services running WordPress. Current focus is on WordPress site operators, which is defensible but could be sharpened for Hostingpaper's audience.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Rejected library image #28: The candidate depicts riot police with shields, which is unrelated to WordPress security, vulnerabilities, or PHP execution. The alt text and URL slug do not match the article topic, and there is no clear connection to the technical subject matter.
- Assigning hero image — Reused library image reused image #3
- Linking related stories — Linked 4 relations from 334 candidates
- Publishing — Published wordpress-core-csrf-flaw-enables-php-execution
- Mastodon — Posted https://mstdn.social/@hostingpaper/117310775743015942



Discussion · coming soon
Be the first to join the thread when community discussion launches.