wp2shell WordPress RCE Flaw: Patch to 6.9.5 or 7.0.2 Now
🔴 Critical | Source: The Hacker News A critical unauthenticated remote code execution vulnerability, dubbed wp2shell, exists in WordPress core versions 6.9 and 7.0, meaning any site running a default installation — with no plugins — could be fully compromised via a single anonymous HTTP request. WordPress has patched the flaw in versions 6.9.5 and 7.0.2 and has pushed forced auto-updates to affected sites. The vulnerability was discovered by Adam Kues at Assetnote, the attack surface management arm of Searchlight Cyber. ...