wp2shell: Unauthenticated RCE in WordPress Core — Patch Every Site Now
A pre-authentication remote code execution flaw in WordPress Core, dubbed wp2shell, lets attackers seize unpatched sites with a single crafted HTTP request. No credentials, no plugins, no special configuration required. With WordPress powering the majority of African business websites, this one demands action today. Hadrian and Searchlight Cyber are urging WordPress administrators to update immediately…