Wire · technology
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 18 July 2026 · Fusion42 review
A critical unauthenticated remote code execution vulnerability in WordPress Core (wp2shell) allows attackers to execute arbitrary code without authentication. The flaw affects a fundamental WordPress component, posing immediate risk to millions of WordPress-powered sites globally.
This Wire brief sits within Fusion42's coverage of Cybersecurity.
◆ ◆ The Wire takeaway
If you build on WordPress or serve WordPress shops, your customers' sites are now actively exploitable without login. Patch this week, then call every client running outdated core—this will be weaponised immediately.
◆ Coverage
1 source · 18 Jul 2026
◆ Related on Wire
◆ Topics