WordPress Click2Shell flaw lets hackers execute PHP on the server

2026-09-21T19:23:20Z•7a62e25515dd8cf531e086b8b0f316fdb7d159c22049f83de6507068dd2dac85
AI securityCSRFClick2ShellNorth KoreaPHP executionWordPressbrowser extensionsdata breachinfostealermalwarenpm supply chainphishing-resistant authenticationproof of conceptransomwareremote code executionsandbox escape

What happened

A BleepingComputer security feed highlights a newly disclosed WordPress Core CSRF vulnerability dubbed Click2Shell, for which technical details and a proof-of-concept reportedly enable PHP execution on the server. The feed also covers npm supply-chain malware, AI sandbox escapes, malicious browser extensions targeting AI agents, major campaigns and breaches, and authentication and backup security developments.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
7a62e25515dd8cf531e086b8b0f316fdb7d159c22049f83de6507068dd2dac85
Enrichment time
2026-09-21T19:23:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.