News Radar RSS

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

The Hacker News Cybersecurity Score 8/10

Summary

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until

Original Text

json { "observation": { "metric": "checkout.conversion_rate", "unit": "percent", "current_value": 3.28, "baseline_value": 4.21, "change": { "relative_pct": -22.1, "absolute_percentage_points": -0.93 } }, "baseline_definition": { "description": "Mean conversion rate for the same 30-minute interval", "lookback": "previous 7 days" }, "scope": { "service": "pricing-engine", "deployment": "pricing-2026-06-15.1" }, "time_window": { "start": "2026-06-15T10:15:00Z", "end": "2026-06-15T10:45:00Z" }, "as_of": "2026-06-15T10:46:03Z", "ingest_watermarks": { "default": "2026-06-15T10:45:58Z", "eu-west-1": "2026-06-15T10:44:31Z" }, "known_gaps": [{ "region": "eu-west-1", "detail": "checkout events delayed ~90s" }], "data_cutoff": "ingested_at <= 2026-06-15T10:45:58Z", "metric_definition": { "id": "checkout-conversion-v2.1", "registry_uri

SecurityThreat Intel

News Radar provides aggregated summaries. Full content and copyright remain with the original publisher.