Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
The Hacker News
3 weeks ago

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

By info@thehackernews.com (The Hacker News)

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.