CyberHighSingle-sourceAccelerating
7.1
WordPress CVE-2026-87902 Path Traversal Exploited Within Hours of Disclosure
SecurityWeekLO·1 day ago
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' affecting the platform's Core component. The flaw could allow attackers to execute arbitrary PHP code on the server, potentially leading to full site compromise. The severity and patch status are not yet fully clear, but the public availability of a PoC increases the risk of exploitation.