Critical Pre-Auth RCE Flaw Found in WordPress Core, Dubbed "wp2shell"
Security researcher Adam Kues of Searchlight Cyber disclosed a critical pre-authentication remote code execution vulnerability in WordPress core, named wp2shell, in July 2026.
MEDIUM · PHP, July 18, 2026
curated by Sönke
The flaw could let attackers compromise sites without valid credentials, putting the more than 500 million WordPress-powered websites at risk until patched or mitigated.
Readers’ Forum
No contributions yet — open the debate.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Waiting for your click …
·