VMTech
Discuss a project

wp2shell in WordPress: a public exploit is already driving mass scanning and site compromise

wp2shell in WordPress: a public exploit is already driving mass scanning and site compromise

Colleagues, I’d like to draw your attention to a cybersecurity incident: the wp2shell vulnerability chain is actively being exploited in WordPress.

I see several risks here:
- the attack works without authentication;
- SQL injection and remote code execution are possible;
- after compromise, attackers create admin accounts, deploy malicious plugins, and install web shells.

What is especially alarming is the mass scanning: after the exploit was published, attackers began broadly hunting for vulnerable sites.

Why this matters: even after patching, it is worth checking new accounts, plugins, files, and activity logs.

Have you already reviewed your WordPress instances?
#cybersecurity #WordPress #VulnerabilityManagement #ThreatIntelligence

Open analytics
On the site 7 views
min read 1 21.07.2026
On Instagram 4 views
On Instagram 1 reach
Instagram

wp2shell in WordPress: a public exploit is already driving mass scanning and site compromise

Open the post on Instagram ↗