Article may be outdated

This article is 3 days old. Some details may have changed since publication.

Internet·2 min read·hard

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code - The Hacker News

T
The Hacker News
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code - The Hacker News
AI Summary

A critical vulnerability in the WordPress core has been identified, allowing unauthenticated attackers to execute arbitrary code. A proof-of-concept is now publicly available, increasing the risk for site administrators.

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story be…

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technology

Get the full story

Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.

Create free account

Already have an account? Sign in