Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
A vulnerability identified as 'WP2Shell' is facilitating remote takeovers of WordPress websites.
2 independently checked trend briefs about this subject, newest first.
headlinez.news detected 2 source-qualified news clusters connected to Wordpress between July 18, 2026 and July 21, 2026. They span 1 newsroom category and average 5.5 independent sources per brief.
This hub includes only briefs supported by at least four sources and passed by the site's verification gate. Raw or weak detections may exist but are excluded here. Topic matching is based on the entities and themes recorded with each brief; open a card to inspect its source links, publication time, verification label and velocity history. Read the methodology and editorial policy for the full rules.
A vulnerability identified as 'WP2Shell' is facilitating remote takeovers of WordPress websites.
A critical remote code execution vulnerability, identified as wp2shell, has emerged in WordPress core, allowing unauthenticated access to websites.