Hackers Exploit Patched WordPress Bugs - Millions of Sites Still at Risk

A critical vulnerability chain in the WordPress REST API, dubbed 'WP2Shell,' allows unauthenticated attackers to gain remote code execution on millions of sites. Security experts urge administrators to update to version 7.0.2 immediately to prevent exploitation.
Why it matters
Because WordPress powers a massive portion of the internet, this vulnerability poses a systemic risk to global web security and data integrity.
Your WordPress site has zero plugins installed. Fresh deployment, bone-stock configuration. And it’s already vulnerable to full remote takeover — no login required. A chainable pair of bugs in the WordPress REST API, dubbed “WP2Shell,” lets attackers turn your site into their personal command line. WordPress 7.0.2 patches the flaws. The problem: tens of millions of sites haven’t updated yet, and automated exploit scanners are already sweeping the web like robocall bots that never sleep — the kind of computer problems that demand immediate action.
Two chained bugs in core WordPress grant unauthenticated attackers full site access on default installations.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in