New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Unauthenticated RCE in WordPress core ('wp2shell') now has a public exploit—given WordPress's dominance in European web infrastructure, this demands emergency patching.
Summary written by editorial AI · Source link below
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it.
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until
Editorial Analysis
WordPress powers a vast portion of European business websites; an unauthenticated RCE with a public exploit creates an imminent mass-exploitation window.
Immediately patch all WordPress instances to the latest core version and deploy WAF rules to block wp2shell exploit patterns.
A critical, publicly exploitable flaw in WordPress core threatens any organisation running the platform and requires immediate remediation.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Vulnerabilities Desk
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More20 Jul
- Mythos Didn't Break Your Security Program. Your Exposure Window Could.20 Jul
- [NEU] [hoch] Extreme Networks ExtremeXOS: Mehrere Schwachstellen20 Jul
- [NEU] [hoch] Grafana: Schwachstelle ermöglicht Manipulation von Dateien20 Jul
- [NEU] [hoch] IBM Langflow Desktop OSS: Mehrere Schwachstellen20 Jul