Attackers actively exploiting patched WordPress WP2Shell flaw chain

Attackers actively exploiting patched WordPress WP2Shell flaw chain

Cybersecurity firms Patchstack, Hexastrike, and WatchTowr confirmed in-the-wild exploitation of two WordPress flaws patched July 17 in version 7.0.2. The critical bug, WP2Shell, enables unauthenticated remote code execution and full site takeover when chained with a second patched vulnerability. Public exploit code appeared July 19. WordPress enabled forced updates where possible; Cloudflare is blocking known attack signatures.

Published

Read at another depth