On Friday, July 17, 2026, the WordPress Security Team released security updates for WordPress Core addressing two vulnerabilities that, when chained together, can lead to unauthenticated remote code execution. The chain, now commonly referred to as wp2shell, was discovered and reported by Adam Kues of Assetnote / Searchlight Cyber, and we want to thank him for his work and responsible disclosure.
WordPress released patched versions 6.8.6, 6.9.5, and 7.0.2 on July 17. The WordPress release notes describe the update as addressing one critical and one high severity security issue, and state that forced automatic updates were enabled for affected versions
Click here to continue reading this article.
