WordPress Core wp2shell RCE Vulnerabilities Now Have Public Exploits

Over 40% of all websites run on WordPress, and public exploits dramatically shorten the window for attackers to compromise unpatched installations.

Abstract geometric illustration representing software vulnerability and the urgency of security patching
AI-generated illustration · Sylvaris

Critical Remote Code Execution Flaws

Security researchers have published working exploit code for critical remote code execution vulnerabilities in WordPress Core, collectively known as wp2shell. The flaws allow attackers to execute arbitrary code on vulnerable WordPress installations without authentication.

The public release of exploit code transforms these vulnerabilities from theoretical risks into active threats. Administrators now face a compressed timeline to apply patches before automated scanning tools begin targeting vulnerable sites at scale.

Immediate Patching Required

WordPress administrators should update to the latest Core version immediately. The availability of public exploits means attackers no longer need specialized knowledge to target these vulnerabilities.

Organizations running WordPress should prioritize this update above routine maintenance. Sites that delay patching risk full compromise, including database theft, malware injection, and unauthorized administrative access.

Widespread Exposure

WordPress powers more than 40 percent of all websites globally, making these vulnerabilities particularly significant. The platform's popularity means millions of sites are potentially affected.

Security teams should verify patch status across all WordPress instances in their infrastructure. Automated update mechanisms may not have deployed the fix uniformly, especially in environments with custom configurations or update policies.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.