
Hackers actively exploiting patched WordPress WP2Shell flaw
Patchstack, Hexastrike, and WatchTowr confirmed active exploitation of two WordPress vulnerabilities patched July 17 in version 7.0.2. The WP2Shell chain enables unauthenticated remote code execution and full site takeover. Public exploit code appeared July 19. WordPress pushed forced updates where possible; Cloudflare is blocking known attack signatures.
Published