Critical wp2shell WordPress flaws exploited to install webshells

Critical wp2shell Vulnerabilities Allow Hackers to Install Webshells and Malicious Plugins

A critical vulnerability suite, known as “wp2shell,” has been exploited by hackers to deploy persistent webshells and install malicious plugins on WordPress installations. The vulnerability, which affects WordPress Core versions prior to 7.0.2, 6.9.5, and 6.8.6, allows remote attackers to execute code without authentication, making it a serious threat to vulnerable websites.

The exploit chain abuses the WordPress REST API’s batch-processing feature, allowing hackers to bypass traditional security measures such as login credentials. Once a website is compromised, hackers can install malicious plugins, deploy webshells, and even query the WordPress REST API to collect sensitive information. A proof-of-concept exploit emerged over the weekend, shortly after SearchLight Cyber disclosed the wp2shell security issue.

Cloud security company Wiz has shared technical details about observed attacks leveraging wp2shell. According to their findings, hackers performed mass-scanning for vulnerable installations, abused plugin upload functionality to install malicious add-ons, and installed PHP webshells disguised as plugins. Hackers also attempted to collect administrator usernames and email addresses through the WordPress REST API.

The exploitation of wp2shell has been observed in various stages, including probing SQL injection to confirm vulnerability before delivering a PHP webshell to the server. In some cases, hackers even created rogue administrator accounts. Johannes B. Ullrich, Dean of Research at Sans Technology Insitute, published a detailed report on the two-stage attacks, describing how they used webshells to execute commands and accessed them through URL requests.

WordPress security firm Defiant has reported that the first exploitation-related probing was observed just hours after the vulnerability was disclosed, followed by a clear SQL injection attempt. Administrators of WordPress sites should immediately update to the patched versions, review logs for wp2shell-related requests, inspect installed plugins, and check for rogue PHP file additions or newly created admin accounts.

A dashboard created by Macnica researcher Yutaka Sejiyama helps track the patch rate live, reporting an 81.6% patch rate out of a sample of 124,580 websites evaluated. SearchLight Cyber researcher Adam Kues has also published a follow-up report diving deep into the process of discovering wp2shell and developing a working exploit chain.

To mitigate the risk of wp2shell exploitation, it is essential to prioritize security updates and regularly review website logs for suspicious activity. Security teams should also test every layer before attackers do – as seen in a recent whitepaper by Picus, which highlights the importance of breach and attack simulation tests in detecting threats that slip through traditional detection methods.


Source: Bleeping Computer — 2026-07-21