SECURITYMALWAREBYTES LABS
What happens if you visit a WordPress site hacked through wp2shell?
WordPress patched a critical core vulnerability chain called wp2shell, which allows attackers to gain full control of sites without authentication, leading to risks like credential theft, malware delivery, and malicious redirects for visitors. Attackers have already begun exploiting the flaw, injecting harmful content and compromising user trust.
Mentioned
Related Signal
Adjacent reporting
- 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now
- Attackers pummel critical WordPress vuln to create all sorts of mischief