Unauthenticated RCE in WordPress core (wp2shell), via SQL injection
✦ NabkaNews BriefAuto-summarized from multiple outlets · verify with the source
A critical vulnerability in wordpress core, known as wp2shell, has been discovered, allowing for unauthenticated remote code execution via sql injection. The vulnerability is being actively exploited, with public exploits available. Multiple sources are advising immediate patching to mitigate the issue, which is associated with cve numbers, though specific details of the exploits and patches may vary.
Full coverage
12345678