22/07/2026
A critical WordPress vulnerability is being actively exploited right now.
It's called wp2shell. No login needed, no plugin required. Just a crafted API request and an attacker has full control of your server.
WordPress 6.8, 6.9, and 7.0 are all affected. A public proof-of-concept exploit is already out there.
If you haven't updated yet, do it now.
We broke down exactly what this vulnerability is, how it works, and the step-by-step fix on the blog.
Check the link in comment. π