Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Hackers are actively exploiting recently patched WordPress vulnerabilities, exposing millions of websites to remote takeover.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Threat actors are targeting WordPress sites via vulnerabilities known as 'WP2Shell.' These bugs allow for remote code execution, potentially giving attackers full control over millions of affected websites. Coverage from TechCrunch, Dark Reading, and SecurityWeek emphasizes that these vulnerabilities are being exploited in the wild.
The Hacker News also included the WordPress remote code execution (RCE) issue in its latest weekly security recap. Future developments center on the scale of the impact and whether further exploits emerge alongside other current threats, such as SonicWall and SharePoint 0-days.
Synthesized by Archynetys from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 5h ago.
Quick answers
What is WP2Shell?
WP2Shell refers to the vulnerabilities in WordPress that allow for remote takeover of websites.
How many sites are potentially at risk?
According to coverage, millions of WordPress sites are at risk.
What type of attack is being used?
The attacks involve remote code execution (RCE) exploiting recently patched bugs.
Coverage (4)
- 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover Dark Reading · 1d ago
- WP2Shell WordPress Vulnerabilities Exploited in the Wild SecurityWeek · 1d ago
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More The Hacker News · 1d ago
- Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk TechCrunch · 1d ago
Topics
Related trends
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
Millions of US vehicles are vulnerable to remote hacking and paralysis due to hidden anti-theft devices installed by dealers.
Lockscreen bug can let hackers bypass security via Gemini AI on Android phone; Google to roll out security fix soon
A security vulnerability in Android allows Gemini AI to send messages from locked devices without requiring a PIN.
RedHook Android malware can quietly hijack your phone
An upgraded version of RedHook Android malware is hijacking devices and stealing banking credentials, primarily targeting users in Southeast Asia.
Hugging Face says it resorted to a Chinese AI model to battle a fully autonomous cyberattack because U.S. model guardrails stymied its defense
Hugging Face reports using a Chinese AI model to counter the first confirmed autonomous AI agent breach of a major AI platform.
Israel Counters Iranian Spying by Warning Against Recruitment
Israel is enlisting rabbis and Haredi influencers to counter Iranian efforts to recruit spies within specific communities.
Google fixing Android lock screen bug that lets Gemini send SMS without a PIN
Google is addressing a security vulnerability allowing Gemini to send SMS messages from locked Android devices without requiring a PIN.