Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits

July 19, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: securityaffairs.com

Threat Risk: High
Victim: WordPress website administrators
Incident: Public release of the wp2shell exploit chain targeting WordPress Core.
Impact: Complete site compromise via pre-authentication remote code execution.
Attacker: Unidentified threat actors
Analysis: Researchers discovered a chain involving a REST API confusion bug and an SQL injection flaw that enables pre-authentication remote code execution. This attack requires no preconditions and affects stock installations of WordPress versions 6.9.x and 7.0.x. The severity is so high that the WordPress team has enabled forced automatic updates for affected sites.
Recommendations: Update WordPress Core to version 7.0.2 or 6.9.5 immediately.; Implement WAF rules to block anonymous access to the /wp-json/batch/v1 endpoint if patching is delayed.; Use the Searchlight Cyber checker tool to verify if your instances remain vulnerable.
Source: Security Affairs

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *