logo

wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution

ID: 4a996102-f32e-5331-a71c-a2d08d98a5e3

STIX ID: report--4a996102-f32e-5331-a71c-a2d08d98a5e3

Feed Name: Elastic Security Labs

Threat Score
80/100

Date Published: 2026-07-23

Date Updated: 2026-08-26

Author: Ruben Groenewoud,Bryan Porras Blanch

...
...

Searchlight Cyber disclosed "wp2shell", a pre-auth remote code execution chain in WordPress Core with public PoCs appearing rapidly; the report walks a lab run of the Icex0 PoC, shows live telemetry of exploitation (web server spawning shells, plugin directories created, access-log markers), maps detection rules that fire (file-creation and web-server-to-shell behavioral rules), and provides network/host IOCs and mitigation guidance (patch to 7.0.2 or 6.9.5 and block REST batch endpoints if immediate patching is not possible).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.