• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Sci-Fi

Hackers are mass-exploiting two WordPress vulnerabilities

July 21, 2026
Share on FacebookShare on Twitter

If you run a WordPress site, the advice this week is blunt: update it now. Two flaws in the software are under active exploitation across the internet.

WordPress powers more than half of every website online, so the blast radius is huge. Security firms say the attacks began within hours of the fix. An AI model sits on both sides of the story.

What wp2shell is

WordPress shipped the patches on Friday, in versions 7.0.2 and 6.9.5. It switched on forced auto-updates because of the risk. Researchers call the flaw wp2shell.

It combines two bugs. One is a SQL injection issue. The other, rated critical at 9.8 out of 10 by TechRadar, is a route confusion bug in the REST API that lets a request skip authentication. Apart, they are fiddly. Chained, they hand an anonymous attacker full remote control.

The đź’ś of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

“The attack has no preconditions,” said Searchlight Cyber, whose researcher Adam Kues found and reported it. It works on a stock WordPress install with no plugins.

AI found it, and AI is weaponising it

Here is the part that unsettles the security world. Kues did not find the chain by hand. He used OpenAI’s GPT-5.6 in about 10 hours, work his firm reckoned could fetch $500,000 from exploit brokers.

The same tools cut the other way. “Reproducing them with the help of frontier AI models was only a matter of time and tokens,” watchTowr researcher Jake Knott told The Register. His team recreated the critical bug within minutes.

watchTowr’s founder, Benjamin Harris, put the shift plainly to SecurityWeek. Proof-of-concept exploits appeared within hours, he said, where they once took a day. “The window between disclosure and exploitation has collapsed.”

What the attackers are doing

By early Saturday, the attacks were well underway. First came public exploit code to steal hashed passwords. Then came remote code execution, as more detail leaked out.

watchTowr’s honeypots logged tens of thousands of attempts and more than 100 backdoor admin accounts, created by different groups. VulnCheck verified more than two dozen distinct exploits by Sunday.

Once inside, attackers plant fake plugins, harvest credentials, and pull in more tooling. In one case, watchTowr watched a group try to install Overlord RAT, a remote-access trojan. Another payload hid a web shell inside a bogus security plugin.

How many sites are exposed

Nobody has a precise count. More than 400 million sites run the affected versions, though many have since patched. The consultant Daniel Card told TechCrunch he sampled around 3,500 sites and put the vulnerable share below 15%, which still works out near 90 million.

Data from Wiz, now owned by Google, told a similar story to The Hacker News. It found 60% of organisations running WordPress had at least one exposed instance when the bugs went public. A quarter had a vulnerable server facing the internet.

The damage was blunted by defences already in place. WordPress forced auto-updates, Cloudflare blocked attacks at its firewall, and Automattic said its hosted sites were protected before the patch even shipped.

The bigger warning

The risk is still real for anyone who lagged. Matt Mullenweg, WordPress’s co-founder, called it a kind of pre-authentication takeover seen only a few times in the software’s 23-year history. It caps a rough run of WordPress security scares.

Knott’s advice is starker. Any site that waited until Monday to patch is probably already compromised, he said, so check for stray admin accounts even after updating. This is the newest sign that AI security now moves at machine speed, weeks after an AI agent breached Hugging Face on its own. Defenders have to keep pace.

Next Post

The 'stunning, behemoth' Galaxy Tab S10 Ultra just scored a $350 discount during Best Buy's Black Friday in July sale

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • X finally ships its rebuilt Android app
  • Darkest Dungeon Is Getting New DLC, Even Though It Has A Sequel
  • Best Buy’s Black Friday in July sale: Big savings on Apple, TCL, Samsung, and way more
  • Google expands Gemini 3.5 line with trio of new models — and shares an update on Gemini 3.5 Pro
  • ‘Love Island’ stars can’t accept every post-villa offer. Here’s why.

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously