Post #4027112
2026-07-23 04:46 UTC
Hey gang, if you still have anything parked on a #wordpress install, make sure you've updated. The latest in a long list of security issues is a pretty serious critical vulnerability.
The critical #exploit abuses the WordPress REST API’s batch-processing feature, allowing remote attackers to execute code on vulnerable installations without the need to authenticate.
Administrators of WordPress sites should immediately update to the patched versions, review logs for wp2shell-related requests, inspect installed plugins, and check for rogue PHP file additions or newly created admin accounts.
https://www.bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/
#zeroday #patch
Replies (0)
No replies.