WordPress patches a newly disclosed “Click2Shell” vulnerability affecting the platform’s Core component. The flaw is described as a cross-site request forgery (CSRF) issue that can be abused to trigger actions from an authenticated user’s browser. Researchers report that it may allow attackers to automatically install and preview themes, a step that could be leveraged toward server-side PHP execution and potential remote code execution.

According to technical reporting, a proof-of-concept and exploitation details are publicly available, increasing the urgency for users to update. SecurityWeek and Bleeping Computer both describe the practical impact as moving from theme installation and previewing to code execution on the server. While coverage emphasizes different aspects—one focusing on the exploit mechanics and proof-of-concept details, the other on the patch and expected risk—both agree the vulnerability is addressed via WordPress updates.