logo

What happens if you visit a WordPress site hacked through wp2shell?

ID: 784bdc41-3d65-57e8-8d24-b4150cb80bbe

STIX ID: report--784bdc41-3d65-57e8-8d24-b4150cb80bbe

Feed Name: Malwarebytes Blog

Threat Score
78/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

...
...

WordPress patched the critical "wp2shell" core vulnerability chain that enables unauthenticated remote code execution and full site takeover; attackers began exploiting the flaw within hours of the patch, injecting malicious JavaScript, redirects, and fake login prompts to steal credentials, deliver malware, and perpetrate scams. Site owners should patch immediately and users should exercise caution on compromised sites and consider browser-based protection such as Malwarebytes Browser Guard.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.