Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
A vulnerability identified as 'WP2Shell' is facilitating remote takeovers of millions of WordPress sites, drawing urgent warnings from security researchers.
2 independently sourced, verified trend briefs about this subject.
Newsylist includes a story here only after at least four independent sources support it and its brief passes the verification check. The qualifying coverage spans 1 news category, from Jul 18, 2026 through Jul 21, 2026.
The cards below are ordered newest first. Each opens the underlying timeline, source list, coverage velocity and verification context; raw or extractive-only records are excluded.
A vulnerability identified as 'WP2Shell' is facilitating remote takeovers of millions of WordPress sites, drawing urgent warnings from security researchers.
A critical remote code execution flaw dubbed 'wp2shell' allows unauthenticated attackers to run code within WordPress Core via SQL injection.