Public exploits have been released for critical Remote Code Execution (RCE) vulnerabilities affecting WordPress Core and the WP2Shell utility. These flaws allow unauthenticated attackers to gain unauthorized access and execute arbitrary commands on the host server, potentially leading to a complete site takeover. Security researchers have warned that the availability of public proof-of-concept (PoC) code significantly increases the risk of widespread exploitation.
Administrators and webmasters are strongly urged to apply the latest security patches immediately to mitigate these risks. In addition to updating, it is recommended to monitor for any unusual file uploads or unauthorized shell activity, as these vulnerabilities bypass standard security controls to facilitate direct server interaction.
Top comments (0)