← Back

Wire · technology

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Published

18 July 2026

Topic

technology

Sectors

Cybersecurity

Source

Read at thehackernews.com

Verified

Fusion42 · 18 July 2026 · Fusion42 review

A critical unauthenticated remote code execution vulnerability in WordPress Core (wp2shell) allows attackers to execute arbitrary code without authentication. The flaw affects a fundamental WordPress component, posing immediate risk to millions of WordPress-powered sites globally.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

If you build on WordPress or serve WordPress shops, your customers' sites are now actively exploitable without login. Patch this week, then call every client running outdated core—this will be weaponised immediately.

Coverage

1 source · 18 Jul 2026

Related on Wire

Topics

Cybersecuritywordpress-securityrce-vulnerabilityunauthenticated-exploitcore-flawcritical-patch