WordPress Core Crisis: The 'wp2shell' Flaw That Left Millions Exposed
A severe security vulnerability dubbed 'wp2shell' has been discovered within the WordPress core, impacting versions 6.9 and 7.0. This flaw is particularly dangerous because it allows unauthenticated attackers to execute remote code on default installations without requiring any active plugins or user interaction. By sending a specific anonymous HTTP request, a malicious actor could gain full control over a site. Security updates 6.9.5 and 7.0.2 have been released to mitigate this threat, which previously left a massive portion of the web vulnerable to total compromise even in the most basic configurations.