WordPress Click2Shell flaw lets hackers execute PHP on the server
BleepingComputer reports a WordPress flaw dubbed Click2Shell that lets hackers execute PHP on the server. The article, published September 21, 2026, provides no further detail in the supplied text about the vulnerability's technical cause, the affected WordPress versions, or the plugin or component involved. The stated consequence is that attackers can run PHP code on the server. No exploitation status, patch availability, or remediation guidance is included in the source text.
The report says the flaw allows PHP execution on the server, which is the kind of capability that can let an attacker run code in a WordPress environment.


