
Critical WordPress Core Vulnerability 'wp2shell' Enables Unauthenticated Remote Code Execution
CybersecurityVulnerabilitiesHackingWebSecurityWordPress
A critical WordPress core vulnerability, dubbed 'wp2shell,' allows unauthenticated attackers to execute arbitrary code via an anonymous HTTP request, affecting even bare installations with no plugins. The flaw impacts all WordPress sites running versions 6.9 and 7.0 until patched, with assigned CVE IDs now disclosed. Technical details, including the full exploitation mechanism and a persistent-object-cache condition, have been publicly released alongside a working proof-of-concept. The update on July 18, 2026, confirmed the vulnerability’s scope and availability of mitigation information. No authentication or additional prerequisites are required for exploitation.