New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
CYBERSECURITY FEATURED ANALYSIS

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

BY

The Hacker News

SOURCE

The Hacker News

DATE

READ

1 min read

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of …

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until