WP2Shell WordPress Exploit Technical Analysis and Real Attack Data

On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by unauthenticated attackers to create an administrator account and then execute code through normal administrator capabilities, such as uploading a plugin. The chain consists of two vulnerabilities: an unauthenticated SQL injection vulnerability identified … Read more

Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced

On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical Authentication Bypass backdoor in Advanced Responsive Video Embedder, a WordPress plugin with approximately 20,000 active installations, less than two hours after the malicious code was introduced. This is not a conventional coding mistake, it’s a supply chain attack that has … Read more

Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)

Last week, there were 75 vulnerabilities disclosed in WordPress Core, 68 WordPress Plugins and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 50 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our … Read more

wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade

On Friday, July 17, 2026, the WordPress Security Team released security updates for WordPress Core addressing two vulnerabilities that, when chained together, can lead to unauthenticated remote code execution. The chain, now commonly referred to as wp2shell, was discovered and reported by Adam Kues of Assetnote / Searchlight Cyber, and we want to thank him … Read more