@lauren@mastodon.laurenweinstein.org
Post #4052974
2026-07-24 03:26 UTC
WARNING: MAJOR new WordPress vulnerability!!!
A very new major vulnerability affecting recent versions of WordPress, likely millions of running instances, is currently being massively exploited in the wild.
The exploit permits unauthenticated users to gain administrative access and control.
The typical pattern is that the exploit gains control, changes the administrator password, creates a number of additional administrators and attempts to access "xmlrpc.php" to morph the site into a malware, etc. distribution site.
If the xmlrpc.php is already blocked on the site, the exploit possibly may not proceed further immediately, but would still leave the additional new administrative users behind.
There are several mitigation techniques even if you are running a vulnerable site and cannot upgrade. The key points are to block the main exploit entry point, remove the additional administrative user entries, and ideally block remote access to the main WordPress login page itself.
More info including a test for vulnerability is at:
https://wp2shell.com/
L
Replies (4)
-
@Ascendor@social.tchncs.de 2026-07-24 04:55
@lauren@mastodon.laurenweinstein.org that's not new. It's known for one week and has been wildly attacked already. In times of AI assisted attacks, a few hours is new. Not a few days. Who hasn't patched yet is probably compromised already.
-
@dilmandila@mograph.social 2026-07-24 05:21
@lauren@mastodon.laurenweinstein.org The link appears broken to me... But what does a non-techie do to fix the problem?
-
@BartV@mastodon.social 2026-07-24 06:40
@lauren@mastodon.laurenweinstein.org TL;DR: always apply WordPress updates
-
@moses_izumi@fe.disroot.org 2026-07-24 10:19
@lauren@mastodon.laurenweinstein.org wordpress is the load-bearing anal cancer of the internet