New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Article summary
Quick briefing — cleaned from the original RSS feed
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until
1Key Takeaways
- Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public.
- An anonymous HTTP request can run code on a WordPress site.
- The bug is in core, so a bare install with zero plugins is exploitable.
- Every 6.9 and 7.0 site was in range until.
2AIWedia Score
7.7/10
Solid update — useful context for the AI space
Based on source trust, recency, category impact, and story depth.
3Why it matters
Developer tooling news affects CI/CD, observability, and how AI ships in production. The Hacker News reports that updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public.
Explore related
Browse toolsDeveloper Tools news
Explore curated developer tools tools on AIWedia — compare, rank, and launch from our directory.
Full story on The Hacker News
Read full articleHeadlines aggregated via RSS for discovery on AIWedia. Original content © The Hacker News. We link to the source and do not republish full articles.