Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Hackers are actively exploiting recently patched WordPress vulnerabilities, exposing millions of websites to remote takeover.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Threat actors are targeting WordPress sites via vulnerabilities known as 'WP2Shell.' These bugs allow for remote code execution, potentially giving attackers full control over millions of affected websites. Coverage from TechCrunch, Dark Reading, and SecurityWeek emphasizes that these vulnerabilities are being exploited in the wild.
The Hacker News also included the WordPress remote code execution (RCE) issue in its latest weekly security recap. Future developments center on the scale of the impact and whether further exploits emerge alongside other current threats, such as SonicWall and SharePoint 0-days.
Synthesized by Archynetys from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 1h ago.
Quick answers
What is WP2Shell?
WP2Shell refers to the vulnerabilities in WordPress that allow for remote takeover of websites.
How many sites are potentially at risk?
According to coverage, millions of WordPress sites are at risk.
What type of attack is being used?
The attacks involve remote code execution (RCE) exploiting recently patched bugs.
Coverage (4)
- 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover Dark Reading · 20h ago
- WP2Shell WordPress Vulnerabilities Exploited in the Wild SecurityWeek · 20h ago
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More The Hacker News · 20h ago
- Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk TechCrunch · 20h ago
Topics
Related trends
Lockscreen bug can let hackers bypass security via Gemini AI on Android phone; Google to roll out security fix soon
A security vulnerability in Android allows Gemini AI to send messages from locked devices without requiring a PIN.
RedHook Android malware can quietly hijack your phone
RedHook Android malware has returned in an upgraded form, capable of hijacking devices and stealing sensitive banking credentials.
Hugging Face says it resorted to a Chinese AI model to battle a fully autonomous cyberattack because U.S. model guardrails stymied its defense
Hugging Face utilized a Chinese AI model to repel a fully autonomous cyberattack after U.S. model guardrails hindered its defense efforts.
Israel Counters Iranian Spying by Warning Against Recruitment
Israel is enlisting rabbis and Haredi influencers to counter Iranian efforts to recruit spies within specific communities.
Google fixing Android lock screen bug that lets Gemini send SMS without a PIN
Google is addressing a security vulnerability allowing Gemini to send SMS messages from locked Android devices without requiring a PIN.
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A critical pre-authentication remote code execution vulnerability known as 'wp2shell' is impacting WordPress Core.