Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
A vulnerability identified as 'WP2Shell' is facilitating remote takeovers of millions of WordPress sites, drawing urgent warnings from security researchers.
Quick answers
What is the WP2Shell vulnerability?
It is a set of vulnerabilities in WordPress that allows for remote takeovers of websites.
Are these vulnerabilities being exploited?
Yes, reports from SecurityWeek and other outlets confirm the bugs are being exploited in the wild.
How many sites are at risk?
According to coverage from TechCrunch and Dark Reading, the vulnerabilities affect millions of WordPress sites.
The brief
Security vulnerabilities collectively known as 'WP2Shell' are being exploited in the wild. The flaws allow unauthorized actors to perform remote takeovers of affected websites.
These security gaps impact a significant number of WordPress installations. Coverage from Dark Reading, SecurityWeek, The Hacker News, and TechCrunch highlights the active nature of these exploits.
Future developments will track the rate at which administrators apply the necessary patches. Coverage does not yet specify the total number of compromised sites or the duration the vulnerability has been accessible to exploiters.
Synthesized by Newsylist from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (86% supported) Updated 44d ago.
Sources (4)
- 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover Dark Reading · 46d ago
- WP2Shell WordPress Vulnerabilities Exploited in the Wild SecurityWeek · 46d ago
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More The Hacker News · 46d ago
- Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk TechCrunch · 46d ago broke it first
How fast it spread
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
People, places & organizations
Topics
Related trends
White House AI Guidelines Exempt U.S. Open Models From Government Review
The White House prepares a new framework for artificial intelligence security reviews with exemptions for open models.
Ariana Grande Sues Over Yearslong Hacking Campaign Targeting Inner Circle
Ariana Grande has filed a lawsuit against alleged hackers following a yearslong campaign targeting her inner circle and leaking unreleased music.
Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Microsoft is challenging industry leaders with a new in-house cybersecurity AI model and an agentic system designed to lower costs.
Microsoft Unveils A.I. Cybersecurity Tools
Microsoft is entering the "agentic era" of security with the launch of its first homegrown AI model and new cybersecurity tools.
Angelina Jolie and Robert De Niro at centre of contact detail ‘leak’
A data breach at the Tribeca Film Festival has resulted in the exposure of private contact information for high-profile Hollywood figures.
Claude Cowork escaped sandbox on Mac, gain full access to all files
Security experts have identified a vulnerability allowing the Claude Cowork AI agent to bypass virtual machine isolation and access local files on Mac systems.