Critical Pre-Auth RCE Flaw Found in WordPress Core, Dubbed "wp2shell"
Security researcher Adam Kues of Searchlight Cyber disclosed a critical pre-authentication remote code execution vulnerability in WordPress core, named wp2shell, in July 2026. The flaw could let attackers compromise sites without valid credentials, putting the more than 500 million WordPress-powered websites at risk until patched or mitigated.
Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.