{"id":244319,"date":"2026-09-21T21:27:52","date_gmt":"2026-09-22T02:27:52","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/09\/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server"},"modified":"2026-09-21T21:27:52","modified_gmt":"2026-09-22T02:27:52","slug":"wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/09\/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server","title":{"rendered":"WordPress Click2Shell flaw lets hackers execute PHP on the server"},"content":{"rendered":"<p><\/p>\n<p><iframe style=\"display: block; margin: 0 auto; width: 100%; aspect-ratio: 4\/3; object-fit: contain;\" src=\"https:\/\/www.youtube.com\/embed\/uLzyPYReGJs?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; encrypted-media; gyroscope;\n   picture-in-picture\" allowfullscreen><\/iframe><\/p>\n<p>Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed \u2018Click2Shell\u2019 that affects the platform\u2019s Core component.<\/p>\n<p>The security problem does not have an official identifier but was addressed last week with the release of <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-1-1\/\" rel=\"nofollow noopener\" target=\"_blank\">WordPress version 7.1.1<\/a>.<\/p>\n<p>It is a pre-authenticated remote code execution chain that allows an attacker to install any theme in the official WordPress.org catalog and run an arbitrary PHP file.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed \u2018Click2Shell\u2019 that affects the platform\u2019s Core component. The security problem does not have an official identifier but was addressed last week with the release of WordPress version 7.1.1. It is a pre-authenticated remote code execution chain [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1492],"tags":[],"class_list":["post-244319","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=244319"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244319\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=244319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=244319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=244319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}