WordPress Core RCE exploits now public, patching urgent
Critical remote code execution flaws in WordPress Core have working public exploits, forcing immediate patching across millions of sites.
Public exploit code is now circulating for critical remote code execution vulnerabilities in WordPress Core, designated "wp2shell." The flaws allow unauthenticated attackers to execute arbitrary code on vulnerable installations.
WordPress powers approximately 43 percent of all websites globally, making the exposure surface substantial. The release of working exploits transforms these vulnerabilities from theoretical risks into active threats. Administrators who delay patching now face adversaries with ready-made attack tools.
BleepingComputer reports the vulnerabilities affect WordPress Core itself, not third-party plugins or themes. This distinction matters: Core flaws require action from every WordPress operator, regardless of their plugin stack or configuration choices.
- 01WordPress site operators face immediate compromise risk without patching
- 02Hosting providers may see surge in scanning and exploitation attempts
- 03E-commerce and corporate sites risk data exfiltration and defacement
- 04Managed WordPress services must coordinate rapid customer updates
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.