The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

The Php Times

Security — Ecosystem

Critical Pre-Auth RCE Flaw Found in WordPress Core, Dubbed "wp2shell"


Security researcher Adam Kues of Searchlight Cyber disclosed a critical pre-authentication remote code execution vulnerability in WordPress core, named wp2shell, in July 2026.

MEDIUM · PHP, July 18, 2026 curated by Sönke

The flaw could let attackers compromise sites without valid credentials, putting the more than 500 million WordPress-powered websites at risk until patched or mitigated.

Read the original source ↗

Rate this article: 0

Readers’ Forum

No contributions yet — open the debate.

← Ecosystem — Page B1

"All the Code That's Fit to Ship" · The Daily Commit · Screen edition · Imprint · Privacy Policy