LIVE
News Internet

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code - The Hacker News

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code - The Hacker News

WordPress 6.9.5 and 7.0.2 patch wp2shell, a pre-auth core RCE that lets anonymous attackers run code on default installs, even with no plugins.

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story be… [+6128 chars]

Discussion (0)

No comments yet. Be the first to share your thoughts!

Join the Conversation

You need to be logged in to leave a comment.

Sign In Create Account