New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
By DAPSSA AI Desk | 2026-07-19T05:36:33.030Z

Overview
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until
Key Developments
This reflects an evolving cybersecurity situation.
Technical Details
Attackers may use automation and vulnerabilities.
Impact & Risks
Potential disruption and data exposure.
Conclusion
Organizations must stay vigilant.
Read more: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html