logo

WordPress Core "wp2shell" RCE Flaws Get Public Exploits — Patch Now

ID: 723069c0-8229-5c42-a0f8-01ee92ab492a

STIX ID: report--723069c0-8229-5c42-a0f8-01ee92ab492a

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

...
...

Public exploit code has been released for a critical WordPress Core remote code execution vulnerability named "wp2shell," creating a high risk of mass exploitation; administrators are urged to update WordPress immediately, enable auto-updates and WAFs, check for compromise indicators (unexpected admin users, PHP files in uploads, modified core files), and apply hardening steps listed in the report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.