New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
ID: d6c35b5b-51b4-5aa9-a6c7-08f9f1b63597
STIX ID: report--d6c35b5b-51b4-5aa9-a6c7-08f9f1b63597
Feed Name: CosmicBytez Labs
**wp2shell — Critical pre-auth RCE in WordPress core (patched 6.9.5 / 7.0.2 on 2026-07-17):** an unauthenticated remote code execution flaw in WordPress core allowed attackers to run arbitrary PHP/shell commands, read wp-config.php, write files and deploy web shells on sites running affected 6.9.x and 7.0.x releases (affecting a large portion of the web); WordPress pushed emergency patches and forced auto-updates, and administrators are advised to update immediately and audit for compromise (unexpected PHP files in uploads/themes/plugins, modified files, unknown admin accounts, and suspicious POST requests).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
