WordPress 6.9.5 and 7.0.2 patch wp2shell, a pre-auth core RCE that lets anonymous attackers run code on default installs, even with no plugins.
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story be… [+6128 chars]
Discussion (0)
No comments yet. Be the first to share your thoughts!
Join the Conversation
You need to be logged in to leave a comment.
Sign In Create Account