Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities FortiGuard Threat Signal

WordPress Core Unauthenticated RCE (WP2Shell)

WP2Shell is a critical unauthenticated remote code execution (RCE) vulnerability chain in WordPress Core, allowing attackers to compromise default installations without requiring plugins or user authentication via exploitation of SQL injection and REST API batch requests. Affected versions include WordPress 6.9.0 through 6.9.4, 7.0.0 through 7.0.1, and the 7.1 Beta. Organizations must immediately upgrade to patched releases 6.9.5 or 7.0.2 and should also monitor for unauthorized admin accounts and suspicious REST API batch endpoint requests.
Read Full Article →

What is the Attack? FortiGuard Labs is observing increasing exploitation activity targeting WP2Shell, a critical unauthenticated remote code execution (RCE) attack chain affecting WordPress Core. Unlike most WordPress attacks that rely on vulnerable plugins or themes, WP2Shell impacts the WordPress core application itself, allowing attackers to compromise default installations without requiring any plugins or authentication. Public proof-of-concept (PoC) exploits are widely available, and active exploitation has been reported shortly after technical details were disclosed. Successful exploitation may allow attackers to: • Execute arbitrary code on the web server. • Create unauthorized administrator accounts. • Deploy web shells or persistent backdoors. • Steal sensitive website and database contents. • Install malware or ransomware. • Use compromised servers for further attacks. What is the recommended Mitigation? Affected Versions: WordPress 6.9.0 – 6.9.4 WordPress 7.0.0 – 7.0.1 WordPress 7.1 Beta Organizations should immediately: • Upgrade WordPress to the latest patched release (6.9.5, 7.0.2, or later). • Restrict unnecessary exposure of WordPress administrative interfaces. • Monitor for unauthorized administrator account creation. • Review web server logs for suspicious REST API batch endpoint requests. • Scan for web shells and other indicators of compromise. • Apply network protections capable of detecting SQL injection and exploitation attempts. What FortiGuard Coverage is available? FortiGuard IPS Service - Detects and blocks exploitation attempts targeting the WP2Shell vulnerability chain. Intrusion Prevention | FortiGuard Labs FortiGuard Web Application Firewall (WAF) - Protects against SQL injection and malicious REST API requests. Web Application Security | FortiGuard Labs FortiGuard Web Filtering - Blocks access to known malicious infrastructure. FortiGuard Antivirus & Behavior Detection - Detects malware and web shells deployed after successful exploitation. FortiGuard IOC Service - Identifies indicators associated with compromised WordPress servers. FortiGuard Incident Response - Assists with investigation, containment, and recovery following compromise.

Share this article