wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
ID: 4a996102-f32e-5331-a71c-a2d08d98a5e3
STIX ID: report--4a996102-f32e-5331-a71c-a2d08d98a5e3
Feed Name: Elastic Security Labs
Date Published: 2026-07-23
Date Updated: 2026-08-26
Author: Ruben Groenewoud,Bryan Porras Blanch
Searchlight Cyber disclosed "wp2shell", a pre-auth remote code execution chain in WordPress Core with public PoCs appearing rapidly; the report walks a lab run of the Icex0 PoC, shows live telemetry of exploitation (web server spawning shells, plugin directories created, access-log markers), maps detection rules that fire (file-creation and web-server-to-shell behavioral rules), and provides network/host IOCs and mitigation guidance (patch to 7.0.2 or 6.9.5 and block REST batch endpoints if immediate patching is not possible).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
