home.social

#wp2shell — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #wp2shell, aggregated by home.social.

fetched live
  1. A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; CVE-2026-63030 + CVE-2026-60137), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing…

    If you haven't already, update your Wordpress (preferably yesterday…; >=v7.0.2 or >= 6.9.5) and also enable automatic updates for themes and plug-ins!

    I found several PHP backdoors/webshells (see @abuse_ch Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops and github.com/ruppde/yara_rules.

    tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates.

    Hashes:
    1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966
    05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da
    bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf
    1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8
    8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab
    e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c
    165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5
    b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6
    a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8
    7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf
    ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09

  2. Уязвимость wp2shell вылезает за пределы webroot: почему патча WordPress недостаточно и как вычистить сервер

    Недавно сообщество WordPress столкнулось с массовой волной взломов через уязвимость в REST Batch API (также известную как wp2shell ). Вектор атаки позволяет злоумышленникам удаленно выполнять произвольный код (RCE) без авторизации. В сети уже появились десятки стандартных гайдов: "Обновите ядро до 6.9.5/7.0.2, удалите подозрительные файлы из /wp-content/uploads/ , поменяйте соли в wp-config.php и очистите базу через SQL" . Спойлер: В 80% случаев на реальных VPS/VDS этого недостаточно.

    habr.com/ru/articles/1068468/

    #wp2shell #wordpress #уязвимости #взлом #патч

  3. @bekopharm @Moepmoep
    Ok, mystery solved:

    They were dormant admin accounts all created during the #wp2shell window (the "normal" attack didn't go through there, as some directories were read-only, but I apparently, an alternate vector was to create admin accounts).

    Thanks again for letting me know about it!

  4. Für #WordPress gab es gestern mit Version 7.0.3 wieder ein Sicherheits-Update.

    Nicht ganz so kritisch wie #wp2shell, aber gerade bei mehreren Benutzern schon "unschön".

    Das Update solltet ihr automatisch bekommen haben, das wurde direkt von WordPress erzwungen.

    Aber auch mal eine gute Gelegenheit, nicht mehr genutzte Plugins und Themes zu prüfen und ggf. zu löschen - was nicht da ist, kann auch nicht angegriffen werden.

    wordpress.org/news/2026/08/wor

  5. 700 IP addresses *EVERY* day that are actively trying to do the #wp2shell.

    They were not blocked by our useragent or other firewall measures, so ... we block them on sight :)

    And yes all WP sites are up to date.

    klarned.is/

  6. Vrijdagmiddag: de wachtrij met gehackte websites wordt alsmaar langer. Zojuist met 1 gestart, maar klant heeft al 2 andere genoemd en ik vermoed dat het daar niet bij zal blijven, want onderhoud werd niet echt gedaan en de lijst met sites was onlangs nog veel langer. Het lijkt inmiddels wel iets meer door te dringen, dat er structureel iets moet gebeuren.

    #WordPress #wp2shell

  7. #wp2shell - die ersten Zeichen für die erwartbare Eskalation !

  8. 🚨 Aggiornamento su #WP2Shell

    Le PoC sono ormai pubbliche e stanno emergendo i primi casi di sfruttamento reale.

    Se hai aggiornato WordPress, non fermarti alla patch: verifica anche account amministrativi, file sospetti, checksum e log.

    Nel video spiego come funziona la vulnerabilità e quali controlli eseguire dopo l’aggiornamento.

    🎥👇

    youtu.be/uzU2tLNsW_U

    #WordPress #CyberSecurity @sicurezza

  9. Wer sein #WordPress noch nicht auf 7.0.2 aktualisiert hat , sollte dies wirklich direkt machen, denn die #wp2shell Sicherheitslücke ist wirklich gravierend! Das #Update steht bereits seit Freitag zur Verfügung! #wpsecurity heise.de/news/WordPress-Luecke

  10. WP2Shell colpisce direttamente il core di WordPress e può portare fino all’esecuzione di codice remoto.

    Nel nuovo video spiego cosa succede, quali versioni sono coinvolte e perché aggiornare potrebbe non bastare.

    🎥 Guarda il video: youtu.be/uzU2tLNsW_U

    #WordPress #WP2Shell #Cybersecurity @linux @sicurezza

  11. Ach ja: Ich bin haarscharf an #wp2shell vorbeigekommen.

    Im Wordpress-Uploads-Ordner waren schon zwei ZIP-Files mit einer Webshell & co drin. Gedroppt ca. 10 Minuten, bevor ich Wordpress aktualisieren konnte.

    Ich betreibe einige Wordpress-Instanzen, die meisten mit Autoupdates aktiv. Das ist aber die älteste, die ein spezielles Setup hat, bei dem ich Autoupdate nicht aktivieren kann. Zum Glück hat derselbe Grund, der Autoupdates verhindert, auch das Aktivieren der Webshell verhindert.

    Phuh!

  12. Critical #WordPress exploit #wp2shell.

    Update sites immediately:

    WordPress 6.9.0 – 6.9.4, fixed in 6.9.5
    WordPress 7.0.0 – 7.0.1, fixed in 7.0.2
    WordPress 7.1 beta, fixed in 7.1 beta2

    cybernews.com/security/critica

    #selfhosted #homelab #cybersecurity

  13. The wp2shell WordPress RCE lets attackers chain flaws into remote code execution. Update to a patched version now, as hackers exploited it within hours.

    #WordPress #RCE #wp2shell #CyberSecurity #AI

    securityexpress.info/wp2shell-

  14. Pour information, nous partageons nos configurations pour Apache/Nginx/HAProxy permettant d'empêcher l'exploitation de cette faille #wp2shell ou, même si l'on a WordPress à jour, de couper l'accès aux (trop) nombreux bots tentant de l'exploiter :

    paste.evolix.org/?169eaaa4d229

  15. 🚨 Critical #wp2shell flaw exposes WordPress core to zero-plugin server takeover! Deep dive into how CVE-2026-63030 and CVE-2026-60137 chain together to achieve unauthenticated Pre-Auth RCE. Full technical analysis:

    denizhalil.com/2026/07/20/word

    #WordPress #CyberSecurity

  16. So, more explanation of wp2shell recently just popped out.

    The vulnerability were found by GPT 5.6 Sol. By using modified prompt from how it found the solution of Cycle Double Cover conjecture.

    It was initially found a SQL Injection, but after asked again if it can be elevated to RCE, it confirms it in 4 hours.

    Technical explanation on the vulnearbility also can be found in this writeup, have a good read fellas.

    slcyber.io/research-center/exp

    #cybersecurity #infosec #security #wordpress #chatgpt #gptsol #wp2shell #airesearch #llm #vulnerability #vulnerabilityresearch

  17. LET OP: ZEG JE "MANAGED" HOSTING NU PER DIRECT OP!

    ALS ... jouw managed host ook vrijdag en dit weekend zijn geld aan het tellen was en je site(s) niet heeft gepatched of geupgrade.

    Ik bedoel (oprecht) ... *managed* hosting moet jouw site beveiligen, stabiel en snel houden. Zit jij nu wel bij de juiste partij?

    Zien we je snel? klarned.is/nl/ Uiteraard hebben we 30 dagen niet-goed-geld-terug, ook op servers.

    Referentie wordpress.org/news/2026/07/wor

    #wp2shell #managed #hosting #wordpress

  18. Mettez à jour rapidement votre CMS #WordPress : faille de sécurité critique !

    Vérifiez avant s'il est exposé à la faille #wp2shell :
    flibustierformation.com/faille/

  19. Il y a une faille critique sur WordPress #wp2shell permettant la prise de contrôle à distance. WordPress a publié des mises à jour pour corriger, notamment la version 7.0.2 : github.com/WordPress/wordpress
    De façon générale, nous vous conseillons fortement d'avoir les mises à jour automatiques de WordPress activées.

    Plus de détails sur wp2shell.com/

  20. @wdormann

    Just had a quick squiz at some servers I run with WordPress on based on the URLs mentioned in the article
    egrep -ir "rest_route=/batch/v1|wp/v2/categories|wp/v2/users" /var/log/apache2/*

    21 requests starting 18/07/2026 05:30 UTC
    None of the requests have anything in common.

    Seems mostly like people poking around rather than spraying at this stage.

    #WordPress #CVE-2026-63030 #CVE-2026-60137 
    #wp2shell