WordPress Click2Shell flaw lets hackers execute PHP on the server
BleepingComputer published a report titled "WordPress Click2Shell flaw lets hackers execute PHP on the server" on September 21, 2026. The headline states that the flaw, referred to as Click2Shell, allows hackers to execute PHP on the server. That is the full extent of the information available in the supplied source text. The excerpt does not name the affected WordPress core version, plugin, or theme, does not describe the mechanism behind the flaw, and does not state whether exploitation has been observed in the wild. It also does not mention a patch, a fixed version, a CVE identifier, a disclosure timeline, or any vendor response. Because the source provides only the flaw's name and its stated outcome, this digest is limited to those two facts: a WordPress-related issue called Click2Shell exists, and it permits PHP execution on the server according to the report.
The report says the flaw allows PHP execution on the server, which is the kind of capability that can let an attacker run code in a WordPress environment.