CuraSec

Act archived

WordPress Core 'wp2shell' RCE flaws get public exploits

2026-07-19 12:05 UTC · BleepingComputer · read the source ↗ #rce#wordpress#public-exploit
  • Engineer — Act: Public exploits for critical WordPress Core RCE make this urgent regardless of absent KEV/EPSS data — update WordPress Core to the latest patched release immediately and verify any managed hosting environments are also updated.
  • SOC/IR — Plan: No IOCs or TTPs are provided to hunt on now, but given public exploits exist for a widely-deployed web platform, build or tune detections for WordPress exploit traffic (e.g., anomalous POST patterns, webshell indicators in web access logs) before active campaigns arrive.
  • Leader — Plan: This is an engineering-track issue, not board-level — confirm your team has inventoried WordPress instances across the estate and that patching is tracked to completion this week.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.