WordPress Core “wp2shell” RCE flaws get public exploits, patch now

July 18, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: bleepingcomputer.com

Threat Risk: High
Victim: WordPress site administrators
Incident: Discovery and public exploitation of the wp2shell RCE vulnerability chain in WordPress Core.
Impact: Complete site takeover via pre-authentication remote code execution.
Attacker: Unidentified threat actors
Analysis: The ‘wp2shell’ attack leverages a chain consisting of a REST API route confusion bug and a high-severity SQL injection. Because this affects the WordPress core without requiring any plugins, the attack surface is massive. Public proof-of-concept code has already emerged, significantly increasing the risk of automated exploitation.
Recommendations: Update WordPress to version 7.0.2 or 6.9.5 immediately; Block anonymous access to the REST API if immediate patching is not possible; Monitor server logs for suspicious requests to /wp-json/batch/
Source: BleepingComputer

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *