Cybersecurity · 153 views
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it.
AI Summary
A newly discovered vulnerability in the WordPress core, known as wp2shell, allows unauthenticated attackers to execute code on affected websites. This flaw is significant because it can be exploited without requiring any prior authentication or authorization. The bug is present in WordPress versions 6.9 and 7.0, and it can be triggered by a simple HTTP request. This means that even a bare install of WordPress, with no additional plugins, is vulnerable to attack. The full mechanism of the exploit has been published, and a working proof-of-concept is now publicly available. The discovery of this vulnerability highlights the importance of regular security updates and patches for WordPress installations. Users are advised to check their version and apply any available updates to mitigate the risk of exploitation.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedCoverage Context
More from Cybersecurity
Continue reading recent Cybersecurity coverage
- N-able N-central Pre-Auth RCE Flaw Exploited in the WildContinue reading
- Cisco bundles fixes for multiple vulnerabilities, some critical, into one patchContinue reading
- Microsoft adds age-awareness APIs that can tell if users are children, teens, or adultsContinue reading
- Microsoft Plugs Nearly 1,000 Security HolesContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow