P.01Cybersecurity/Vulnerability Management··5 min read
wp2shell: WordPress Core's Zero-Login RCE Chain, What to Patch Right Now
A default WordPress install can now be taken over by a single anonymous HTTP request. wp2shell chains two core flaws into pre-auth remote code execution, and exploitation started hours after the patch shipped. Here's what's affected and the fix.
CybersecurityWordPressCVE
Read